<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-intra-handshake-fail-41" category="info" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Early Attestation Considered Harmful">Early Attestation Considered Very Harmful (CVE-2026-92701 of CVSS 9.1, CVE-2026-92702 of CVSS 9.1, CVE-2026-33697 of CVSS 7.5, and 37 other CVEs of up to expected CVSS 10.0 upcoming)</title>
    <seriesInfo name="Internet-Draft" value="draft-intra-handshake-fail-41"/>
    <author fullname="Muhammad Usama Sardar">
      <organization abbrev="TU Dresden">Technical University of Dresden</organization>
      <address>
        <postal>
          <city>Dresden</city>
          <code>01187</code>
          <country>Germany</country>
        </postal>
        <email>muhammad_usama.sardar@tu-dresden.de</email>
      </address>
    </author>
    <author fullname="Viacheslav Dubeyko">
      <organization>CoreWeave</organization>
      <address>
        <email>slava@dubeyko.com</email>
      </address>
    </author>
    <author fullname="Jean-Marie Jacquet">
      <organization>University of Namur</organization>
      <address>
        <postal>
          <city>Namur</city>
          <country>Belgium</country>
        </postal>
        <email>jean-marie.jacquet@unamur.be</email>
      </address>
    </author>
    <author fullname="Songbo Bu">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>bluedognull@gmail.com</email>
      </address>
    </author>
    <author fullname="Chengxin Huang">
      <organization>Independent</organization>
      <address>
        <email>aurestarnull@gmail.com</email>
      </address>
    </author>
    <author fullname="Haowen Song">
      <organization>Shanghai Guan An Information Technology Co., Ltd.</organization>
      <address>
        <postal>
          <country>China</country>
        </postal>
        <email>havan12050544@gmail.com</email>
      </address>
    </author>
    <author fullname="Kaya Ercihan">
      <organization>Switch</organization>
      <address>
        <postal>
          <city>Zurich</city>
          <country>Switzerland</country>
        </postal>
        <email>kaya.ercihan@switch.ch</email>
      </address>
    </author>
    <author initials="D. K. A." surname="Küçük" fullname="Dr Kubilay Ahmet Küçük">
      <organization>DPhil Oxford University</organization>
      <address>
        <email>dr.kucuk@oxfordalumni.org</email>
      </address>
    </author>
    <author fullname="Serhii Nikolaichuk">
      <organization>The Capital Index</organization>
      <address>
        <postal>
          <city>Austin, Texas</city>
          <country>USA</country>
        </postal>
        <email>nikolaichuk.s.f@gmail.com</email>
      </address>
    </author>
    <author fullname="Sylvain Bellemare">
      <organization>Sureshot Labs</organization>
      <address>
        <postal>
          <country>Japan</country>
        </postal>
        <email>sbellem@gmail.com</email>
      </address>
    </author>
    <author initials="E. C. M." surname="Willems" fullname="Eva C. M. Willems">
      <organization>Independent</organization>
      <address>
        <postal>
          <country>Netherlands</country>
        </postal>
        <email>evac.m.willems@proton.me</email>
      </address>
    </author>
    <author fullname="Justin DESSENNES SAINTEN">
      <organization>Independent Corporate Risk Consultant</organization>
      <address>
        <postal>
          <city>Paris</city>
          <country>France</country>
        </postal>
        <email>dessennes_sainten@msn.com</email>
      </address>
    </author>
    <author fullname="Massimiliano Brighindi">
      <organization>PHI-OMEGA</organization>
      <address>
        <postal>
          <city>San Benedetto del Tronto</city>
          <country>Italy</country>
        </postal>
        <email>phiomega.runtime@gmail.com</email>
      </address>
    </author>
    <author fullname="Mikerah Quintyne-Collins">
      <organization>HashCloak Inc and Stoffel Labs Inc</organization>
      <address>
        <postal>
          <country>Canada</country>
        </postal>
        <email>mikerah@hashcloak.com</email>
      </address>
    </author>
    <author fullname="Iman Schrock">
      <organization>EMILIA Protocol, Inc.</organization>
      <address>
        <email>team@emiliaprotocol.ai</email>
      </address>
    </author>
    <date year="2026" month="September" day="23"/>
    <workgroup>SEAT</workgroup>
    <keyword>AI agents</keyword>
    <keyword>Intra-handshake attestation</keyword>
    <keyword>Early attestation</keyword>
    <keyword>CVE-2026-33697</keyword>
    <keyword>CVE-2026-92701</keyword>
    <keyword>CVE-2026-92702</keyword>
    <abstract>
      <?line 296?>

<t>The draft aims to provide technical details of <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="CVE-2026-92701"/>, <xref target="EUVD-2026-83194"/>, <xref target="CVE-2026-92702"/>, <xref target="EUVD-2026-83192"/> and several GitHub Security Advisories (GHSAs) which provide substantial technical evidence of how early attestation fails in practice, even <strong>without physical access</strong> to the desired machine. Moreover, since continuous attestation is generally required <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, early attestation adds <strong>unnecessary complexity</strong>. The results are backed by the research <xref target="Intra-handshake.fail"/>, <xref target="TLS-RA"/>, <xref target="EarlyAttestationBleed"/> and the artifacts <xref target="Intra-handshake.fail-repo"/> in state-of-the-art formal analysis tool, ProVerif, under Apache-2.0 license for reproducibility, extensibility, and review, and have been acknowledged by the relevant stakeholders. Currently, there are <strong>two CVEs of CVSS 9.1, one CVE of CVSS 7.5, one GHSA of 9.0-10.0, one GHSA of CVSS 7.8, seven GHSAs of CVSS 7.4, and one GHSA of CVSS 6.3 published against the broader early attestation covering all layers of the ecosystem up to the application</strong>. The research papers on these are currently either under submission or being prepared for submission. The artifacts of these papers will be shared with the community under Apache-2.0 license for reproducibility, extensibility, and review. In our analysis, the remaining implementations of early attestation -- Edgeless Systems Contrast and Meta's AI -- remain vulnerable.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://muhammad-usama-sardar.github.io/intra-handshake-fail/draft-intra-handshake-fail.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-intra-handshake-fail/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail"/>.</t>
    </note>
  </front>
  <middle>
    <?line 300?>

<section anchor="introduction">
      <name>Introduction</name>
      <t><xref target="Intra-handshake.fail"/> presents a general approach to analyze the intra-handshake (aka early) attestation proposals, regardless of whether they are within the scope of SEAT charter or not. From a security perspective, one of the key decision factors is the candidate binding mechanism. Some binding mechanisms are within scope of SEAT charter and others are not. The artifacts are available in <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 license for reproducibility, extensibility and further research.</t>
      <t>A <strong>complementary</strong> paper <xref target="ID-Crisis"/> presents the identity crisis in pre- and intra-handshake attestation. The formal analysis is available in <xref target="ID-Crisis-repo"/> under Apache-2.0 license for reproducibility and extensibility.</t>
      <t>Another complementary paper -- currently under submission -- performs a thorough formal analysis of the design options in intra-handshake attestation.</t>
      <section anchor="overview">
        <name>Overview</name>
        <t><xref target="Intra-handshake.fail"/> presents the formal specification and analysis of the candidate binding mechanisms for binding in intra-handshake attestation for standardization for attested TLS protocols:</t>
        <table>
          <name>Binding mechanisms, implementations and ProVerif artifacts</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Used in</th>
              <th align="left">Artifacts</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">-</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MarkusRudy.contrast-atls-ccc-attestation.pdf">Edgeless Systems Contrast</eref>; <eref target="https://www.sns-itrust6g.com/wp-content/uploads/2025/12/Webinar-Architecting-Trust-CONFIDENTIAL6G.pdf">Cocos AI v0.8.2</eref>;  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>; <eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI updated spec</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <xref target="I-D.fossati-tls-attestation-06"/></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7">binder7</eref></td>
            </tr>
          </tbody>
        </table>
        <artwork><![CDATA[
We provide a formal proof of insecurity of all the above candidate
binding mechanisms of intra-handshake attestation using the
state-of-the-art tool ProVerif and propose a mitigation for the
discovered security vulnerabilities. Our study reveals that it may
not be possible to achieve strong application-traffic (level 3)
binding using intra-handshake attestation alone. This can be exploited
for relay attacks, where an attacker makes a client accept an evidence
from a different machine. So the client cannot be sure that it connects
to its desired server.
]]></artwork>
        <t>We responsibly disclosed the vulnerability in intra-handshake attestation -- as noted in <xref target="GHSA-Cocos-AI"/> issued -- to the vendors, which resulted in  <xref target="CVE-2026-33697"/> of CVSS 7.5.</t>
      </section>
      <section anchor="modeling-other-binding-mechanisms">
        <name>Modeling Other Binding Mechanisms</name>
        <t>The artifacts are quite flexible for modification and testing of different intra-handshake attestation binding mechanisms by simply changing single <tt>rdata</tt> parameter in the Client and Server processes. Folder <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/aggregate">aggregate</eref> contains all analyzed and proposed binding mechanisms in <xref target="Intra-handshake.fail"/> to select via comment and uncomment. Other folders contain one specific binding mechanism.</t>
      </section>
      <section anchor="seat-early-attestation">
        <name>SEAT-Early-Attestation</name>
        <t>The draft <xref target="I-D.fossati-seat-early-attestation"/> is an extension of the provably vulnerable (and withdrawn) draft <xref target="I-D.fossati-tls-attestation-10"/> with the following two main changes from a formal perspective:</t>
        <ol spacing="normal" type="1"><li>
            <t>Binder has been updated</t>
          </li>
          <li>
            <t>Optional post-handshake attestation part has been added for re-attestation</t>
          </li>
        </ol>
        <t>The current binder in <xref target="I-D.fossati-seat-early-attestation"/> does not prevent relay attacks as there is no <strong>shared secret</strong> in the binder. In addition to the formal analysis in <xref target="Intra-handshake.fail"/>, see <xref target="TLS-RA"/> for arguments why shared secret is necessary to prevent relay attacks.</t>
        <t>Post-handshake attestation part may prevent relay attacks, but then the <strong>additional complexity</strong> of intra-handshake attestation is unjustified.</t>
      </section>
      <section anchor="executive-summary-of-current-status">
        <name>Executive Summary of Current Status</name>
        <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>. Scores of 13 more GHSAs is yet to be confirmed and will be added later in this table. <strong>For TLS reference, Heartbleed was CVSS 7.5</strong>.</t>
        <table>
          <name>Published CVEs/GHSAs for intra-handshake (aka early) attestation</name>
          <thead>
            <tr>
              <th align="left">CVSS</th>
              <th align="left">Severity</th>
              <th align="left">Number of Published GHSAs</th>
              <th align="left">Number of Published CVEs</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">9.0-10.0</td>
              <td align="left">Critical</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">9.1</td>
              <td align="left">Critical</td>
              <td align="left">2</td>
              <td align="left">2</td>
            </tr>
            <tr>
              <td align="left">7.8</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">7.5</td>
              <td align="left">High</td>
              <td align="left">1</td>
              <td align="left">1</td>
            </tr>
            <tr>
              <td align="left">7.4</td>
              <td align="left">High</td>
              <td align="left">7</td>
              <td align="left">-</td>
            </tr>
            <tr>
              <td align="left">6.3</td>
              <td align="left">Medium</td>
              <td align="left">1</td>
              <td align="left">-</td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="sec-credits">
      <name>Published GHSAs/CVEs</name>
      <table>
        <name>GHSAs/CVEs for intra-handshake (aka early) attestation and finders in (roughly) chronological order of publishing -- CVSS of last 14 GHSAs are preliminary</name>
        <thead>
          <tr>
            <th align="left">GHSA/CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Finders</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI"/></td>
            <td align="left">7.8</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-16488"/></td>
            <td align="left">7.5</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI2"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Cocos-AI3"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Edgeless-Systems2"/></td>
            <td align="left">9.0-10.0</td>
            <td align="left">Markus Rudy; independently by Songbo Bu and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rustls"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-go"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eov"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-eom"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar, Viacheslav Dubeyko, and Jean-Marie Jacquet</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-da"/></td>
            <td align="left">7.4</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="GHSA-Privasys-rtc-tcu"/></td>
            <td align="left">6.3</td>
            <td align="left">Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83194"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EUVD-2026-83192"/></td>
            <td align="left">9.1</td>
            <td align="left">Muhammad Usama Sardar and Songbo Bu</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">9.8</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">9.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">8.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">8.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">8.1</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">7.9</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">7.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">6.5</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">5.6</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">4.4</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">4.2</td>
            <td align="left">Songbo Bu, Chengxin Huang, and Muhammad Usama Sardar</td>
          </tr>
          <tr>
            <td align="left">TBA</td>
            <td align="left">7.8</td>
            <td align="left">Chengxin Huang, Songbo Bu, and Muhammad Usama Sardar</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section anchor="threat-model">
      <name>Threat Model</name>
      <t>The threat model is explained in Sec. 6.1 of <xref target="Intra-handshake.fail"/> and Sec. 4 of <xref target="ID-Crisis"/>.</t>
      <t>Beyond post-generation leakage of <tt>privEK</tt> considered in <xref target="Intra-handshake.fail"/>, the same adversary capability may arise from failures during key generation or entropy provisioning. Platform-attestation keys and workload-controlled TLS keys belong to distinct key-generation domains: for example, in AMD SEV-SNP the VCEK is derived by SNP firmware from chip-unique secrets and a TCB version, while several other platform secrets are specified as CSRNG-generated; by contrast, <tt>privEK</tt> and TLS (EC)DHE private values are typically generated by software executing inside the confidential VM using the guest OS or cryptographic-library random subsystem. Furthermore, SEV-SNP <tt>REPORT_DATA</tt> is supplied by the guest and incorporated into the signed attestation report without being interpreted by SNP firmware; consequently, valid Evidence can authenticate a binding value without attesting the entropy provenance, generation procedure, or exclusive possession of the corresponding private key. The <tt>LEK(privEK)</tt> capability should therefore also encompass predictable or repeated key generation caused by deficient entropy, cloned or rolled-back DRBG state, defective software or firmware, or malicious provisioning. <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">CVE-2025-62626</eref> provides a concrete manufacturer-layer fault model: affected AMD Zen 5 processors could return insufficiently random values from certain <tt>RDSEED</tt> forms while incorrectly signaling success. This does not establish compromise of the AMD-SP-internal CSRNG or of a specific attested-TLS implementation, but demonstrates that ideal-randomness assumptions can fail below the protocol layer; software dependencies such as OpenSSL's <tt>--with-rand-seed=rdcpu</tt> (<eref target="https://github.com/openssl/openssl/blob/openssl-3.5.0/INSTALL.md">OpenSSL 3.5.0 INSTALL.md</eref>), which can use <tt>RDSEED</tt> or <tt>RDRAND</tt> as CSPRNG seed input, illustrate a possible propagation path from hardware entropy interfaces to workload TLS key generation.</t>
      <section anchor="low-level-mapping-of-the-system-model">
        <name>Low-Level Mapping of the System Model</name>
        <t>Figure 2 of <xref target="Intra-handshake.fail"/> provides a TEE-agnostic protocol-level
abstraction. For a low-level view, the following table maps the abstract
components to representative Intel TDX and AMD SEV-SNP implementations.</t>
        <table>
          <name>Mapping of the abstract system model to representative CC implementations</name>
          <thead>
            <tr>
              <th align="left">Fig. 2 element</th>
              <th align="left">Intel TDX</th>
              <th align="left">AMD SEV-SNP</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <strong>Physical Machine</strong></td>
              <td align="left">TDX-capable Intel platform</td>
              <td align="left">SEV-SNP-capable AMD platform</td>
            </tr>
            <tr>
              <td align="left">
                <strong>CC Platform</strong></td>
              <td align="left">CPU HW + TDX Module + attestation infrastructure</td>
              <td align="left">CPU HW + AMD-SP/SNP (system) firmware + RMP/SEV machinery</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Quoting Agent</strong></td>
              <td align="left">TD QE</td>
              <td align="left">AMD-SP / SNP attestation (VM) firmware</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Confidential VM</strong></td>
              <td align="left">Trust Domain (TD)</td>
              <td align="left">Part of SNP confidential VM</td>
            </tr>
            <tr>
              <td align="left">
                <strong>Network stack</strong></td>
              <td align="left">Part of guest OS + TLS library inside TD</td>
              <td align="left">Part of guest OS + TLS library inside SNP guest</td>
            </tr>
            <tr>
              <td align="left">
                <strong>HSM/TPM</strong></td>
              <td align="left">Secure element</td>
              <td align="left">Secure element</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privAK</tt></strong></td>
              <td align="left">Attestation key of TD Quoting Enclave</td>
              <td align="left">VCEK/VLEK signing key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privEK</tt></strong></td>
              <td align="left">Workload/TLS-side ephemeral key</td>
              <td align="left">Workload/TLS-side ephemeral key</td>
            </tr>
            <tr>
              <td align="left">
                <strong><tt>privLTK</tt></strong></td>
              <td align="left">Long-term key in secure element</td>
              <td align="left">Long-term key in secure element</td>
            </tr>
          </tbody>
        </table>
        <t>The key material shown in the abstract model belongs to different implementation
and trust domains. The following table provides a corresponding low-level view.</t>
        <table>
          <name>Low-level implementation and key-generation domains</name>
          <thead>
            <tr>
              <th align="left">Component/key</th>
              <th align="left">Runs/lives where?</th>
              <th align="left">Type</th>
              <th align="left">Randomness/key source</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">TLS ECDHE</td>
              <td align="left">Inside network stack</td>
              <td align="left">Network stack</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">
                <tt>privEK</tt></td>
              <td align="left">Inside confidential VM</td>
              <td align="left">Guest software</td>
              <td align="left">OS/library CSPRNG</td>
            </tr>
            <tr>
              <td align="left">AK</td>
              <td align="left">Quoting Agent</td>
              <td align="left">Firmware/enclave/platform key hierarchy</td>
              <td align="left">Platform-specific</td>
            </tr>
            <tr>
              <td align="left">Memory-encryption key</td>
              <td align="left">CC Platform</td>
              <td align="left">Hardware/firmware managed</td>
              <td align="left">Platform RNG/KDF</td>
            </tr>
            <tr>
              <td align="left">
                <tt>REPORT_DATA</tt></td>
              <td align="left">Created by Guest Software</td>
              <td align="left">Data binding</td>
              <td align="left">No independent entropy requirement</td>
            </tr>
          </tbody>
        </table>
        <t>Per-VM memory-encryption key is used to encrypt confidential VM's RAM.</t>
      </section>
    </section>
    <section anchor="detailed-vulnerability-disclosure-timeline-and-public-acknowledgements-by-affected-vendors">
      <name>Detailed Vulnerability Disclosure Timeline and Public Acknowledgements by Affected Vendors</name>
      <table>
        <name>Detailed vulnerability disclosure timeline and acknowledgements</name>
        <thead>
          <tr>
            <th align="left">Event</th>
            <th align="left">Date</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">Our initial responsible disclosure to vendor</td>
            <td align="left">07 Oct, 2025</td>
          </tr>
          <tr>
            <td align="left">Acknowledgement by vendor</td>
            <td align="left">14 Dec, 2025</td>
          </tr>
          <tr>
            <td align="left">Information to the <eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">IETF</eref></td>
            <td align="left">11 Jan, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://web.archive.org/web/20260227160554/https://www.ultraviolet.rs/blog/tee-tls-privacy/">Public announcement</eref> by vendor</td>
            <td align="left">27 Feb, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>]</td>
            <td align="left">23 March, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-33697"/> published  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-16488"/>  [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">26 March, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/rustls/releases/tag/privasys-v0.8.1">Acknowledgment</eref> by Privasys for rustls <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">9 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/Privasys/go/releases/tag/privasys-v0.5.1-go1.26.5">Acknowledgment</eref> by Privasys for go <xref target="CVE-2026-33697"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</td>
            <td align="left">10 July, 2026</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation</eref> declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref></td>
            <td align="left">17 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable <eref target="https://github.com/ccc-attestation/attested-tls-poc">CCC implementation repo</eref> archived</td>
            <td align="left">22 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Vulnerable draft <xref target="I-D.fossati-tls-attestation-10"/> withdrawn by authors</td>
            <td align="left">23 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">29 July, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI2"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Cocos AI published <xref target="GHSA-Cocos-AI3"/>  [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">16 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Edgeless Systems published <xref target="GHSA-Edgeless-Systems2"/> [<strong>Severity = CRITICAL (CVSS 9.0-10.0)</strong>]</td>
            <td align="left">24 August, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eov"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-eom"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">3 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in rustls and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys archived early attestation in go and moved to post-handshake attestation</td>
            <td align="left">4 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-da"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <xref target="GHSA-Privasys-rtc-tcu"/> [<strong>Severity = MEDIUM (CVSS 6.3)</strong>]</td>
            <td align="left">6 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92701"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">CVE <xref target="CVE-2026-92702"/> published [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83194"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">ENISA published EUVD <xref target="EUVD-2026-83192"/> [<strong>Severity = CRITICAL (CVSS 9.1)</strong>]</td>
            <td align="left">18 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-322v-xwfj-63cm">GHSA-322v-xwfj-63cm</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-m9p9-3hxp-4j6j">GHSA-m9p9-3hxp-4j6j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-ppc4-fg56-x397">GHSA-ppc4-fg56-x397</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6j47-3cm6-9cg6">GHSA-6j47-3cm6-9cg6</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-4755-rh6c-694j">GHSA-4755-rh6c-694j</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-6f8q-88mv-c8vr">GHSA-6f8q-88mv-c8vr</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-qqq3-6c47-684v">GHSA-qqq3-6c47-684v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-xxr6-w252-4ggx">GHSA-xxr6-w252-4ggx</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-fmrx-fjqw-37gp</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fmrx-fjqw-37gp">GHSA-f96w-jjf8-xpw3</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-fqrx-3wc2-4g49">GHSA-fqrx-3wc2-4g49</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-mrgr-34cc-fcg8">GHSA-mrgr-34cc-fcg8</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
          <tr>
            <td align="left">Privasys published <eref target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-wqf9-jfmm-f68v">GHSA-wqf9-jfmm-f68v</eref></td>
            <td align="left">19 September, 2026</td>
          </tr>
        </tbody>
      </table>
      <t><strong>Neither the GHSAs nor the CVEs have any dependency whatsoever on the considered threat model with <tt>WeakHash</tt>, <tt>WeakDH</tt>, or <tt>BadElement</tt>.</strong> They hold independent of those, i.e., with <tt>StrongHash</tt> and <tt>StrongDH</tt> and all good elements within a group.</t>
    </section>
    <section anchor="eu-enisa">
      <name>EU ENISA</name>
      <t>European Union's <eref target="https://euvd.enisa.europa.eu/homepage">ENISA</eref> has independently published <xref target="EUVD-2026-16488"/> with CVSS 7.5 to acknowledge this vulnerability.</t>
    </section>
    <section anchor="sec-cvss-scores">
      <name>Comparison with Other Vulnerabilities in Confidential Computing Literature</name>
      <t>Severity is based on <eref target="https://nvd.nist.gov/vuln-metrics/cvss">NIST metrics</eref>.</t>
      <table>
        <name>Comparison with other vulnerabilities in confidential computing literature</name>
        <thead>
          <tr>
            <th align="left">Vulnerability</th>
            <th align="left">CVE</th>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <eref target="https://wiretap.fail/files/wiretap.pdf">wiretap.fail</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2025-10-28-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3040.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://tee.fail/files/paper.pdf">TEE.fail</eref></td>
            <td align="left">No CVE</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://ddropattack.eu/ddrop.pdf">DDRop</eref></td>
            <td align="left">No CVE (<eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2026-08-11-001.html">Intel</eref> and <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3048.html">AMD</eref> announcements)</td>
            <td align="left">-</td>
            <td align="left">None</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://dl.acm.org/doi/10.1145/3658644.3690230">TDXdown</eref></td>
            <td align="left">
              <eref target="https://www.intel.com/content/www/us/en/security-center/announcement/intel-security-announcement-2024-10-08-001.html">Intel</eref></td>
            <td align="left">2.5</td>
            <td align="left">Low</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/staleus/staleus_usenix26.pdf">Staleus</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-54509">CVE-2025-54509</eref></td>
            <td align="left">4.0</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-6197">CVE-2025-61972</eref></td>
            <td align="left">4.2</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://badram.eu/badram.pdf">BadRAM</eref></td>
            <td align="left">
              <eref target="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html">AMD</eref></td>
            <td align="left">5.3</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/breakfast/breakfast_oakland26.pdf">BreakFAST</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=CVE-2025-61971">CVE-2025-61971</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://xca-attacks.github.io/fabricked/fabricked_usenix26.pdf">Fabricked</eref></td>
            <td align="left">
              <eref target="https://www.cve.org/CVERecord?id=cve-2025-54510">CVE-2025-54510</eref></td>
            <td align="left">5.9</td>
            <td align="left">Medium</td>
          </tr>
          <tr>
            <td align="left">
              <eref target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">Intra-handshake.fail</eref></td>
            <td align="left">
              <xref target="CVE-2026-33697"/></td>
            <td align="left">7.5</td>
            <td align="left">High</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92701"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
          <tr>
            <td align="left">
              <xref target="EarlyAttestationBleed"/></td>
            <td align="left">
              <xref target="CVE-2026-92702"/></td>
            <td align="left">9.1</td>
            <td align="left">Critical</td>
          </tr>
        </tbody>
      </table>
      <t>The comparison of the above with CVSS <strong>9.1</strong> for early attestation indicates that it is not mature yet compared to the rest of the confidential computing stack, and is currently one of the weakest links in the ecosystem.</t>
    </section>
    <section anchor="more-cves">
      <name>More CVEs</name>
      <t>Further formal analysis has led to the following potential CVEs for intra-handshake (aka early) attestation (currently under review and disclosure):</t>
      <table>
        <name>Expected CVEs for intra-handshake (aka early) attestation under review and disclosure</name>
        <thead>
          <tr>
            <th align="left">CVSS</th>
            <th align="left">Severity</th>
            <th align="left">Number of CVEs</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">9.0-10.0</td>
            <td align="left">Critical</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">9.8</td>
            <td align="left">Critical</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">8.7</td>
            <td align="left">High</td>
            <td align="left">1</td>
          </tr>
          <tr>
            <td align="left">7.8</td>
            <td align="left">High</td>
            <td align="left">1 (confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">7.5</td>
            <td align="left">High</td>
            <td align="left">5</td>
          </tr>
          <tr>
            <td align="left">7.4</td>
            <td align="left">High</td>
            <td align="left">9 (5 confirmed by developers)</td>
          </tr>
          <tr>
            <td align="left">6.3</td>
            <td align="left">Medium</td>
            <td align="left">7</td>
          </tr>
        </tbody>
      </table>
      <t>These are preliminary estimates of scores, not final assigned score. They are still under review.</t>
    </section>
    <section anchor="vulnerable-implementations">
      <name>Vulnerable Implementations</name>
      <t>As demonstrated in <xref target="Intra-handshake.fail"/> and <xref target="Intra-handshake.fail-repo"/>, at least the following intra-handshake implementations are vulnerable:</t>
      <ul spacing="normal">
        <li>
          <t><eref target="https://ai.meta.com/static-resource/private-processing-technical-whitepaper">Meta's AI</eref>: <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]</t>
        </li>
        <li>
          <t><eref target="https://github.com/edgelesssys/contrast">Edgeless Systems Contrast</eref>: <xref target="GHSA-Edgeless-Systems"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>]</t>
        </li>
      </ul>
      <t>If you are aware of any other intra-handshake attestation implementation, please let us know so that we can check and responsibly disclose the vulnerabilities to them.</t>
      <section anchor="archivedmitigated-implementations">
        <name>Archived/Mitigated Implementations</name>
        <t>The following intra-handshake implementations were vulnerable and have been <strong>archived</strong> or moved to <strong>post</strong>-handshake attestation:</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref>'s adopted project <eref target="https://github.com/ccc-attestation/attested-tls-poc">intra-handshake attestation</eref>: declared <eref target="https://github.com/CCC-Attestation/attested-tls-poc/pull/58">vulnerable to relay attacks</eref> and <strong>archived</strong></t>
          </li>
          <li>
            <t><eref target="https://github.com/ultravioletrs/cocos">Cocos AI &lt;= v0.8.2</eref>: <xref target="GHSA-Cocos-AI"/>  [<strong>Severity = HIGH (CVSS 7.8)</strong>], <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> [<strong>Severity = HIGH (CVSS 7.5)</strong>]; <strong>migrated</strong> to post-handshake attestation since v0.9.0</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/rustls">Privasys rustls &lt;= privasys-v0.2.0</eref>: <xref target="GHSA-Privasys-rustls"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
          <li>
            <t><eref target="https://github.com/Privasys/go">Pirvasys go &lt;= privasys-v0.3.0-go1.26.5</eref>: <xref target="GHSA-Privasys-go"/> [<strong>Severity = HIGH (CVSS 7.4)</strong>], <strong>archived</strong> and Privasys migrated to post-handshake attestation</t>
          </li>
        </ul>
      </section>
    </section>
    <section anchor="vulnerable-protocol-specifications">
      <name>Vulnerable Protocol Specifications</name>
      <t>At least the following protocol specifications with intra-handshake attestation <em>path</em> are vulnerable to <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/>:</t>
      <ul spacing="normal">
        <li>
          <t><xref target="I-D.fossati-tls-attestation-09"/>: symbolic proof of insecurity; <xref target="I-D.fossati-tls-attestation-10"/> <strong>withdrawn</strong> after the CVE</t>
        </li>
        <li>
          <t><xref target="I-D.fossati-seat-early-attestation"/>: symbolic and (paper-and-pen-based) computational proof of insecurity (originally done for -04 and applies also to -06)
          </t>
          <ul spacing="normal">
            <li>
              <t>As a SEAT WG participant pointed out, please note that both <xref target="CVE-2026-33697"/> and <xref target="EUVD-2026-16488"/> contain a link to <xref target="GHSA-Cocos-AI"/> that contains a link to <xref target="SEAT-vulnerability-report"/> that contains the G3 property (cf. <xref target="sec-corr-goals"/>) that this draft does not satisfy.</t>
            </li>
            <li>
              <t>Some WG participants successfully reproduced the vulnerability by substituting the right value of <tt>rdata</tt> in the shared formal model <xref target="Intra-handshake.fail-repo"/> that led to the CVE.</t>
            </li>
            <li>
              <t>An informal reasoning is that binder is not <strong>directly</strong> derived from any <strong>shared secret</strong> in this draft.</t>
            </li>
            <li>
              <t><strong>Unnecessary complexity</strong> is itself a security concern</t>
            </li>
          </ul>
        </li>
        <li>
          <t><xref target="I-D.ritz-seat-facts"/>: symbolic proof of insecurity
          </t>
          <ul spacing="normal">
            <li>
              <t>violates G3 property in our analysis</t>
            </li>
            <li>
              <t>unnecessary complexity is itself a security concern</t>
            </li>
          </ul>
        </li>
      </ul>
    </section>
    <section anchor="binding-levels">
      <name>Binding Levels</name>
      <ol spacing="normal" type="1"><li>
          <t>DH shared secret (<tt>gxy</tt>) used as shared secret between client and server</t>
        </li>
        <li>
          <t>Handshake traffic key (<tt>htsc</tt>) used for encryption of handshake messages</t>
        </li>
        <li>
          <t>Application traffic key (<tt>atsc</tt>) used for encryption of application data</t>
        </li>
      </ol>
      <t>Please see Sec. 6.2 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="sec-corr-goals">
      <name>Security Properties (Correlation Goals)</name>
      <t>We consider TLS Server as RATS Attester, which is typical in confidential computing.</t>
      <ol spacing="normal" type="1"><li>
          <t>Correlation of Evidence to a DH Shared Secret (G1)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Handshake Traffic Key (G2)</t>
        </li>
        <li>
          <t>Correlation of Evidence to Client’s Application Traffic Key (G3)</t>
        </li>
      </ol>
      <t>Please see Sec. 6.3 of <xref target="Intra-handshake.fail"/> for details.</t>
    </section>
    <section anchor="main-results">
      <name>Main Results</name>
      <ul spacing="normal">
        <li>
          <t>All analyzed binding mechanisms and the corresponding implementations of intra-handshake attestation are vulnerable to relay attacks.</t>
        </li>
        <li>
          <t>Early exporter helps achieve level 1 binding.</t>
        </li>
        <li>
          <t>Our proposed mechanism helps achieve level 2 binding.</t>
        </li>
        <li>
          <t>It may not be possible to achieve level 3 in intra-handshake attestation alone without additional assumptions.</t>
        </li>
      </ul>
      <table>
        <name>Main results</name>
        <thead>
          <tr>
            <th align="left">Property</th>
            <th align="left">Mechanism #1,2,4,6</th>
            <th align="left">Mechanism #3,5,7</th>
            <th align="left">Proposed mechanism</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">G1 : Correlation of Evidence to <tt>gxy</tt></td>
            <td align="left">❌</td>
            <td align="left">✅</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G2 : Correlation of Evidence to <tt>kch</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">✅</td>
          </tr>
          <tr>
            <td align="left">G3 : Correlation of Evidence to <tt>kc</tt></td>
            <td align="left">❌</td>
            <td align="left">❌</td>
            <td align="left">❌</td>
          </tr>
        </tbody>
      </table>
      <t>Please see Sec. 7.1 and Figure 5 of <xref target="Intra-handshake.fail"/> for details of attacks.</t>
      <section anchor="expected-results">
        <name>Expected Results</name>
        <table>
          <name>Expected results</name>
          <thead>
            <tr>
              <th align="left">No.</th>
              <th align="left">Binding mechanism</th>
              <th align="left">Artifacts</th>
              <th align="left">Expected results</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">1.</td>
              <td align="left">Client’s TLS nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/">binder1</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder1/log.txt">binder1</eref></td>
            </tr>
            <tr>
              <td align="left">2.</td>
              <td align="left">Client’s attestation nonce</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/">binder2</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder2/log.txt">binder2</eref></td>
            </tr>
            <tr>
              <td align="left">3.</td>
              <td align="left">Early exporter</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/">binder3</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder3/log.txt">binder3</eref></td>
            </tr>
            <tr>
              <td align="left">4.</td>
              <td align="left">Server’s public key</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/">binder4</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder4/log.txt">binder4</eref></td>
            </tr>
            <tr>
              <td align="left">5.</td>
              <td align="left">Combination of #2 and #3</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/">binder5</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder5/log.txt">binder5</eref></td>
            </tr>
            <tr>
              <td align="left">6.</td>
              <td align="left">Combination of #2 and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/">binder6</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder6/log.txt">binder6</eref></td>
            </tr>
            <tr>
              <td align="left">7.</td>
              <td align="left">Combination of #2, #3, and #4</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/">binder7</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/binder7/log.txt">binder7</eref></td>
            </tr>
            <tr>
              <td align="left">8.</td>
              <td align="left">Proposed</td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/">proposal</eref></td>
              <td align="left">
                <eref target="https://github.com/muhammad-usama-sardar/intra-handshake.fail/tree/main/proposal/log.txt">proposal</eref></td>
            </tr>
          </tbody>
        </table>
      </section>
    </section>
    <section anchor="implications-of-findings">
      <name>Implications of Findings</name>
      <section anchor="implications-of-findings-for-ietf-seat-wg">
        <name>Implications of Findings for IETF SEAT WG</name>
        <ul spacing="normal">
          <li>
            <t>We believe post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>, can achieve level 3 binding.</t>
          </li>
          <li>
            <t>The research suggests that recent hybrid proposals (combination of intra-handshake attestation and post-handshake attestation) <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> may add <strong>unnecessary complexity</strong> of intra-handshake attestation without adding any security benefit compared to post-handshake attestation alone, such as <eref target="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">draft-fossati-seat-expat</eref>. We are not aware of any <strong>security property</strong> that hybrid proposals can achieve that post-handshake attestation alone cannot achieve.</t>
          </li>
          <li>
            <t>As demonstrated by our symbolic analysis using ProVerif, the protocol specifications <xref target="I-D.fossati-seat-early-attestation"/> and <xref target="I-D.ritz-seat-facts"/> remain vulnerable to CVE-2026-33697. We have also proved that <xref target="I-D.fossati-seat-early-attestation-04"/> and <xref target="I-D.fossati-seat-early-attestation"/> violate the security theorems in the computational model.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-lake-wg">
        <name>Implications of Findings for IETF LAKE WG</name>
        <ul spacing="normal">
          <li>
            <t>Similar problems occur for protocol specification <eref target="https://datatracker.ietf.org/doc/draft-ietf-lake-ra/">lake-ra</eref>.</t>
          </li>
        </ul>
      </section>
      <section anchor="implications-of-findings-for-ietf-tls-wg">
        <name>Implications of Findings for IETF TLS WG</name>
        <ul spacing="normal">
          <li>
            <t><xref target="I-D.fossati-tls-attestation-09"/> is vulnerable to <xref target="CVE-2026-33697"/>. Thankfully, the authors have withdrawn <xref target="I-D.fossati-tls-attestation-10"/>.</t>
          </li>
          <li>
            <t>Remote attestation <em>within</em> the handshake is very dangerous, since to our knowledge, it is one of the highest scored published vulnerabilities in confidential computing literature (see <xref target="sec-cvss-scores"/>). For reference, <strong>Heartbleed</strong> was <strong>7.5 CVSS</strong>.</t>
          </li>
        </ul>
        <artwork><![CDATA[
Given the high- and critical-severity vulnerabilities, we recommend
that the developers and maintainers of intra-handshake attestation MUST
urgently move to post-handshake attestation.
]]></artwork>
      </section>
      <section anchor="implications-of-findings-for-agent2agent">
        <name>Implications of Findings for Agent2Agent</name>
        <t>The findings of published CVEs/GHSAs up to 9.1 (presented in <xref target="sec-credits"/>) show that intra-handshake attestation can introduce significant security risks for AI agents when relied upon as a security mechanism.</t>
        <t>Attestation can provide evidence about an agent’s technical state, but such evidence should not be equated with governability. For a relying party, governability also depends on whether the agent’s identity, authority and permissions remain aligned with the intended interaction, whether responsibility for its actions can be attributed, and whether meaningful intervention remains possible. The findings in this draft reinforce that distinction by showing that even the binding between attestation evidence and the intended session can fail. Successful attestation should therefore be treated as one input into governance, rather than as sufficient evidence that an AI agent remains under effective control.</t>
      </section>
    </section>
    <section anchor="technical-details">
      <name>Technical Details</name>
      <section anchor="tool">
        <name>Tool</name>
        <t>We use state-of-the-art symbolic security analysis tool <eref target="https://ieeexplore.ieee.org/document/9833653">ProVerif</eref> for the specification of the protocols.</t>
      </section>
      <section anchor="modeling">
        <name>Modeling</name>
        <t>The formal model uses the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work as the starting point to focus on relay attacks in intra-handshake attestation in this work.
The rationale is that we consider it more useful to show the added value of this contribution to the community by using the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> as the baseline, rather than showing the same diversion attacks from <xref target="ID-Crisis"/>, and the discovered CVE (<xref target="CVE-2026-33697"/>) -- which the previous analysis could not find -- practically demonstrates the added value.
This modeling choice makes it clear that even with the diversion attacks fixed, high-severity relay attacks would still remain in intra-handshake attestation.</t>
        <t>Note: Similar to the <eref target="https://github.com/CCC-Attestation/formal-spec-id-crisis/tree/main/TLS-a/fix">fixed version of diversion attacks in intra-handshake attestation</eref> from our previous work, we model non-PSK-based handshake.
From <xref target="ID-Crisis"/>:</t>
        <ul empty="true">
          <li>
            <t>For modeling TLS 1.3, we consider handshakes based on Diffie-Hellman over either finite fields or elliptic curves, represented as (EC)DHE. This is because we are unaware of any publicly available specification or implementation of attested TLS with PSK-based handshakes.</t>
          </li>
        </ul>
        <t>While it would be nice to model PSK-based handshake, the rationale is that the correlation properties studied in this work do not necessarily require it.</t>
        <t>Note: The artifacts consider the case of server authentication only, as client authentication is optional in TLS 1.3. No claims are made about other configurations.</t>
      </section>
      <section anchor="properties">
        <name>Properties</name>
        <t>Properties in <xref target="Intra-handshake.fail"/> are complemetary to properties in <xref target="ID-Crisis"/>. Sec. 8 of <xref target="ID-Crisis"/> mentions:</t>
        <ul empty="true">
          <li>
            <t>We emphasize that both diversion and relay attacks are orthogonal and thus the two works are complementary.</t>
          </li>
        </ul>
      </section>
      <section anchor="technical-vulnerability-report">
        <name>Technical Vulnerability Report</name>
        <t>Technical vulnerability report is available at <xref target="Intra-handshake.fail"/>. It is accepted for publication at ESORICS 2026.</t>
        <section anchor="vulnerabilities">
          <name>Vulnerabilities</name>
          <t>Sec. 7.1 of <xref target="Intra-handshake.fail"/> presents the technical details with abstract attack traces of the vulnerabilities.</t>
        </section>
        <section anchor="mitigation">
          <name>Mitigation</name>
          <t>Sec. 7.2 of <xref target="Intra-handshake.fail"/> presents the technical details of the proposed mitigation.</t>
        </section>
      </section>
      <section anchor="artifacts">
        <name>Artifacts</name>
        <t>Artifacts are available at <xref target="Intra-handshake.fail-repo"/> under Apache-2.0 License.</t>
      </section>
    </section>
    <section anchor="sec-news">
      <name>Media Coverage</name>
      <t>Several cybersecurity and media professionals and bloggers have covered the vulnerabilities to protect the community from the harm of early attestation.</t>
      <section anchor="earlyattestationbleed">
        <name>EarlyAttestationBleed</name>
        <t><xref target="EarlyAttestationBleed"/></t>
        <ul spacing="normal">
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92701-trusted-execution-environments-0-8-2/">Cybersecurity news (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://cybersecurity-news.de/cve-2026-92702-cocos-ai-0-8-2/">Cybersecurity news (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.anquan114.com/archives/7429">Security 114</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/31Glxqr6ofHylTyrtNsuaQ">KK says security</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="mp.weixin.qq.com/s/REtESPngXemSro0hjIZyxw">Safe Meow Station</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Digital World Information</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://mp.weixin.qq.com/s/864dwIXF5IY04q7ig4uBwg">Shusei Consulting</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/518">Freenode</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>CIRCL's <eref target="https://vulnerability.circl.lu/vuln/CVE-2026-92701">vulnerability.circl.lu (CVE-2026-92702)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92701">db.gcve.eu (CVE-2026-92701)</eref></t>
          </li>
          <li>
            <t>GCVE's <eref target="https://db.gcve.eu/vuln/cve-2026-92702">db.gcve.eu (CVE-2026-92702)</eref></t>
          </li>
        </ul>
        <t>If you have written an article on this and would like to be added here, please send us a PR at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref> or an email with the subject "Media coverage of EarlyAttestationBleed."</t>
      </section>
      <section anchor="intra-handshakefail">
        <name>Intra-handshake.fail</name>
        <t><xref target="Intra-handshake.fail"/></t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref></t>
          </li>
          <li>
            <t>(Japanese) <eref target="https://blackhatnews.tokyo/archives/119915">BlackHatNewsTokyo</eref></t>
          </li>
          <li>
            <t>(Several languages) <eref target="https://hackernoon.com/attested-tls-was-supposed-to-be-the-last-trust-boundary-it-isnt-formal-methods-show-how">Hackernoon</eref></t>
          </li>
          <li>
            <t><eref target="https://podcasts.apple.com/eg/podcast/attested-tls-was-supposed-to-be-the-last-trust/id1698517643?i=1000776623286">Apple podcast</eref></t>
          </li>
          <li>
            <t><eref target="https://meterpreter.org/attested-tls-vulnerability-cve-2026-33697/">Information Security News</eref></t>
          </li>
          <li>
            <t><eref target="https://thenextgentechinsider.com/pulse/critical-flaw-discovered-in-confidential-computing-attestation-protocols">TheNextGenTechInsider</eref></t>
          </li>
          <li>
            <t><eref target="https://dailysecurityreview.com/resources/cve-2026-33697-attested-tls-relay-flaw-hits-whatsapp-cocos-ai/">DailySecurityReview</eref></t>
          </li>
          <li>
            <t><eref target="https://www.scworld.com/brief/confidential-computings-remote-attestation-protocol-may-have-fundamental-flaw">SC World</eref></t>
          </li>
          <li>
            <t><eref target="https://blogs.groupware.org.uk/01-Quantum-Inc/the-handshake-that-cant-keep-its-promise-why-confidential-computings-flaw-changes-the-data-sovereignty-conversation/">01 Quantum</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.securitylab.ru/news/574545.php">Security Lab</eref></t>
          </li>
          <li>
            <t>(German) <eref target="https://www.blogspan.net/confidential-computing-attestierung-relay-luecke/">blogspan</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://finance.sina.cn/tech/2026-07-04/detail-inifscxt9953361.d.html">Sina</eref></t>
          </li>
          <li>
            <t><eref target="https://data4biz.com/articles/una-falla-rompe-la-fiducia-del-confidential-computing">data4biz</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://www.itsec.ru/news/issledovateli-nashli-kriticheskuyu-uyazvimost-v-attested-tls">ITSec</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://post.smzdm.com/p/a82ol990/">smzdm</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://www.donews.com/news/detail/4/6621022.html">donews</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://i.ifeng.com/c/8uUfy0PMmqE">ifeng</eref></t>
          </li>
          <li>
            <t><eref target="https://www.dugganusa.com/post/confidential-computing-s-whole-pitch-is-trust-the-proof-not-the-cloud-two-years-of-formal-verifi">dugganusa</eref></t>
          </li>
          <li>
            <t><eref target="https://github.com/pduggusa/dugganusa-ietf/tree/main/cve-2026-33697-attestation">dugganusa repo</eref></t>
          </li>
          <li>
            <t><eref target="https://sploitus.com/exploit?id=92591A05-07BC-5015-BA3D-B1347B35D684">spoitus</eref></t>
          </li>
          <li>
            <t><eref target="https://news.lavx.hu/article/attested-tls-research-exposes-a-weak-link-in-confidential-computing">lavx news</eref></t>
          </li>
          <li>
            <t><eref target="https://www.sohu.com/a/1045865934_122004016">sohu</eref></t>
          </li>
          <li>
            <t>(Persian) <eref target="https://news.ditty.ir/news/attested-tls-relay-flaw-formal-methods/019f6221-26ca-7293-9ee9-5557b3c0b8f8">news.ditty</eref></t>
          </li>
          <li>
            <t>(Russian) <eref target="https://limpvpn.com/ru/news/attested-tls-whatsapp-privacy-flaw-2026">LiMP VPN</eref></t>
          </li>
          <li>
            <t><eref target="https://daily.dev/posts/kI6PoNzPx">daily.dev</eref></t>
          </li>
          <li>
            <t><eref target="https://warden.veritai.ch/news/researchers-find-attested-tls-flaws-that-weaken-confidential-computing-trust-model">warden</eref></t>
          </li>
          <li>
            <t><eref target="https://db.gcve.eu/sightings/?query=cve-2026-33697">GCVE.eu</eref></t>
          </li>
          <li>
            <t><eref target="https://vulnerability.circl.lu/vuln/CVE-2026-33697#sightings">vuln.lu</eref></t>
          </li>
          <li>
            <t><eref target="https://coderlegion.com/24087/intra-handshake-attestation-when-more-security-doesnt-mean-better-security">coderlegion</eref></t>
          </li>
          <li>
            <t><eref target="https://www.anjuna.io/blog/attested-tls-flaw-explained">Anjuna Security</eref></t>
          </li>
          <li>
            <t><eref target="https://privasys.org/blog/binding-attestation-to-the-tls-session/">Privasys</eref></t>
          </li>
          <li>
            <t><eref target="https://caution.co/blog/steve-attesting-the-session.html">Caution</eref></t>
          </li>
          <li>
            <t><eref target="https://freenode.net/digest/67">freenode</eref></t>
          </li>
          <li>
            <t>(Chinese) <eref target="https://blog.csdn.net/weixin_42376192/category_13096766.html">csdn</eref></t>
          </li>
          <li>
            <t><eref target="https://osintsights.com/confidential-computing-flaws-expose-trust-risks">osintsights</eref></t>
          </li>
          <li>
            <t>(Turkish) <eref target="https://hardwaremania.com/haber/arastirma-attested-tls-confidential-computing-icin-zayif-kaliyor/">hardwaremania</eref></t>
          </li>
          <li>
            <t><eref target="https://akber.com/sovereignty-in-the-cloud-is-an-illusion/">akber</eref></t>
          </li>
          <li>
            <t><eref target="https://www.ad-hoc-news.de/wissenschaft/cloud-souveraenitaet-red-hat-startet-reifegrad-assessments-gegen/69691475">ad-hoc news</eref></t>
          </li>
          <li>
            <t><eref target="https://aimultiple.com/privacy-enhancing-technologies">AIMultiple</eref></t>
          </li>
        </ul>
        <section anchor="security-researchers">
          <name>Security Researchers</name>
          <t>Several credible security researchers, such as the following, have publicly attested to it.</t>
          <ul spacing="normal">
            <li>
              <t><eref target="https://www.linkedin.com/posts/michaelpak_confidential-computings-core-trust-mechanism-activity-7479415537836376064-q-A4/">Michael Pak</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/rrbranco_one-more-evidence-that-there-is-no-such-a-share-7479582122366615552-X0A5/">Rodrigo Branco</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/posts/bart-preneel-4451412_on-the-limits-of-confidential-computing-share-7479549718294077440-wfi3/">Bart Preneel</eref></t>
            </li>
            <li>
              <t><eref target="https://www.linkedin.com/in/strufe/recent-activity/all/">Thorsten Strufe</eref></t>
            </li>
          </ul>
        </section>
        <section anchor="germanys-bsi">
          <name>Germany's BSI</name>
          <t>Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) has attested to it. Carina Hilt, deputy press spokesperson at BSI, told <eref target="https://www.theregister.com/security/2026/07/04/confidential-computings-trust-mechanism-is-broken-the-fix-may-not-exist/5266056">The Register</eref>:</t>
          <artwork><![CDATA[
CC alone cannot satisfy the requirements for digital sovereignty.
]]></artwork>
          <artwork><![CDATA[
dependencies on other services, such as identity and key
management etc., are also not mitigated by CC.
]]></artwork>
          <t>CC refers to Confidential Computing, and attested TLS is the core trust mechanism of CC.</t>
        </section>
      </section>
    </section>
    <section anchor="reviews">
      <name>Reviews</name>
      <section anchor="conference-reviews">
        <name>Conference Reviews</name>
        <t><xref target="Intra-handshake.fail"/> has been peer-reviewed and accepted for publication at ESORICS 2026.</t>
      </section>
      <section anchor="ietfirtf">
        <name>IETF/IRTF</name>
        <t>Several participants of the IETF/IRTF have attested to the results by independently reproducing the results and reviewing the code. Some of the participants have independently reproduced the results by developing their own formal models and a proof-of-concept implementation of the vulnerabilities. Some of the messages are mentioned below (<strong>excluding</strong> the messages of authors of <xref target="Intra-handshake.fail"/>):</t>
        <ul spacing="normal">
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/">https://mailarchive.ietf.org/arch/msg/seat/B7F1Dj_rjs8I0Kg3yCp3Rap0XeE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/">https://mailarchive.ietf.org/arch/msg/seat/aEV9dUFotAQzHndk23qBcwBT3as/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/">https://mailarchive.ietf.org/arch/msg/seat/3Hv0E1sfXsvyBtl6AgY8j-SHHiw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/">https://mailarchive.ietf.org/arch/msg/seat/5LJ6i9svomnhpyPHWPejM7fMmXQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/">https://mailarchive.ietf.org/arch/msg/seat/V_YqGUY3fEwaFwwyfA9DshpHet0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/">https://mailarchive.ietf.org/arch/msg/seat/JF_cwmHHEbrJ_W5V6yEetWWnii4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/">https://mailarchive.ietf.org/arch/msg/seat/P_CYTycg0KG7cbKauFA-kVgX2jo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/">https://mailarchive.ietf.org/arch/msg/seat/ZJjJXpYwZ5nCVmz_W4FK6XiFEY4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/">https://mailarchive.ietf.org/arch/msg/seat/4so3LxHOOXHS1wnvhuoeWWgeCHk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/">https://mailarchive.ietf.org/arch/msg/seat/Q6Jmc58v0c1lDV3ujIY0AX_ofGA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/">https://mailarchive.ietf.org/arch/msg/seat/n4Me5QPCvwhxcEJndWePyishcoo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/">https://mailarchive.ietf.org/arch/msg/seat/beRzNNvwMifkRfJPfxecGoHpTDs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/">https://mailarchive.ietf.org/arch/msg/seat/aFCo4BMRDSUynvN9AQJatPjnXag/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/">https://mailarchive.ietf.org/arch/msg/seat/wb_Ys9MZd9u9oM2Bk-8tv7fvXGg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/">https://mailarchive.ietf.org/arch/msg/seat/ov8f-7cZKK5RZ-Mmjc6IhVSB-Fk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/">https://mailarchive.ietf.org/arch/msg/seat/2uUuaD1DygjNDM4GT_-rYbwTiJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/">https://mailarchive.ietf.org/arch/msg/seat/pB39abN1QrH4_ATM_E78vxPTuxk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/">https://mailarchive.ietf.org/arch/msg/seat/PxKCxMHe-SAiR9uhOOllrK4mUA4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/">https://mailarchive.ietf.org/arch/msg/seat/T1xupUBwqYEBSHCTXgSHXZtdqz8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/">https://mailarchive.ietf.org/arch/msg/seat/hRw46FwgmVdi9fqZm2fjKbln_IA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/">https://mailarchive.ietf.org/arch/msg/seat/UG7yE_klmRSxNy2HX6fzuFonDjM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/">https://mailarchive.ietf.org/arch/msg/seat/2hpeIldeFfE6o9q6L9Vkt00ACKA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/">https://mailarchive.ietf.org/arch/msg/seat/gc2ij0vboehS_-v10-SNslxaZC0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/">https://mailarchive.ietf.org/arch/msg/seat/oO4mAfq5HJZptDDNrSnd7zDdX18/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/">https://mailarchive.ietf.org/arch/msg/seat/XuJc_yEJPCMIuYcv2OM7XDogRCU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/">https://mailarchive.ietf.org/arch/msg/seat/nVHlnbFIEh-cPQeMuDVOqx5YvWQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/">https://mailarchive.ietf.org/arch/msg/seat/xVU3C7qUOngcip7B4ZO5MJUT9Xg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/">https://mailarchive.ietf.org/arch/msg/seat/1gCcPw-7NopDRzzBzA3dFIgo3Rs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/">https://mailarchive.ietf.org/arch/msg/seat/t8aobzB374lWiLzrVrORY7kGYyQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/">https://mailarchive.ietf.org/arch/msg/seat/m3UyB6XLQzxaucejE_o8Pn41uSI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/">https://mailarchive.ietf.org/arch/msg/seat/gqHqcbbKva_oGE-jEDZu243gf-4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/">https://mailarchive.ietf.org/arch/msg/seat/QD8QB1WVL-toNovGQ2Tk6DmmeEM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/">https://mailarchive.ietf.org/arch/msg/seat/vXN2pifZ5GXcC1xLwSfLCnUcFUE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/">https://mailarchive.ietf.org/arch/msg/seat/MGFXinb85XSaLkqjBEhmBZC7PcI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/">https://mailarchive.ietf.org/arch/msg/seat/js9VI4PB8yYmhg2ObaZB1a22fL4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/">https://mailarchive.ietf.org/arch/msg/seat/0RzORzX_VdlY5UQ_MWMmxZlnrjs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/">https://mailarchive.ietf.org/arch/msg/seat/W3MH1BDSUbm1WUPxGQihaIc1zTk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/">https://mailarchive.ietf.org/arch/msg/seat/2_aGylmFHoLmqN7BBcYVoH-rNJk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/">https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/">https://mailarchive.ietf.org/arch/msg/seat/0SWfg2YNEAOtJQ7Zsf1xl4O-AOo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/">https://mailarchive.ietf.org/arch/msg/seat/1mfNw-bw8KsdJbl4saL99Fz4iec/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/">https://mailarchive.ietf.org/arch/msg/seat/VyifG8zP5aworb_S1NR9FEUEXW0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/">https://mailarchive.ietf.org/arch/msg/seat/CYwvM75z6rTId2A3ZZvZJmHxOig/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/">https://mailarchive.ietf.org/arch/msg/ufmrg/29xFZX5C4oSGkpZAvXT_7YLW2Vc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/">https://mailarchive.ietf.org/arch/msg/seat/u1HxYW9cJfVpi3Cf9q06ehwpYGE/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/">https://mailarchive.ietf.org/arch/msg/seat/SG_A0016a-KMnXAkGtMUxokZmjc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/">https://mailarchive.ietf.org/arch/msg/seat/3w7-OW2CAVr0-QBz97eAMxB_nMI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/">https://mailarchive.ietf.org/arch/msg/seat/UnybcafvQ2D-IhUfTV228WQFNhA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/">https://mailarchive.ietf.org/arch/msg/seat/rmVNeFbjax26l31n5pitHIxOQkk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/">https://mailarchive.ietf.org/arch/msg/seat/DghJdG3ysbPFKMQe8czz-tcIMq0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/">https://mailarchive.ietf.org/arch/msg/seat/rZLacid2wnEtaJwSbiIIft3T0FI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/">https://mailarchive.ietf.org/arch/msg/seat/_kEBODNsTWjgadb5xnlj86dvhcs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/">https://mailarchive.ietf.org/arch/msg/seat/qP3XC0MarFFA3SMbBpWWJtxACNA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/">https://mailarchive.ietf.org/arch/msg/seat/kkjQhi4yvJ_iAwYrPw1crFh-m-0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/">https://mailarchive.ietf.org/arch/msg/seat/vBkdKtKzTt4F91VprfKIndgmT2o/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/">https://mailarchive.ietf.org/arch/msg/seat/Huu_AFu11BTrdxK3I8hmw2jjp8Q/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/">https://mailarchive.ietf.org/arch/msg/seat/oOnioxkB__QZIvhFn5naW6jIXzg/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/">https://mailarchive.ietf.org/arch/msg/seat/iWsCCAl8YZ-pOTA7siNUGsfliHQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/">https://mailarchive.ietf.org/arch/msg/seat/-HGPUR5CvuVWcOAg37cSxwoATm0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/">https://mailarchive.ietf.org/arch/msg/seat/LnLYE7bGQOmCxVXq6stiOtKwc1s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/">https://mailarchive.ietf.org/arch/msg/seat/o_bIJhOdB4j1g0nczxPZwFXtCo8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/">https://mailarchive.ietf.org/arch/msg/seat/hy4qVQJQGR82-bskQ_UGI6iel1Y/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/">https://mailarchive.ietf.org/arch/msg/seat/3J3s_YFnf9IQ87Tv2c1q4f36xKQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/">https://mailarchive.ietf.org/arch/msg/seat/JWKMYY1YG1E2iS_HyQ4rDmOsDGw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/">https://mailarchive.ietf.org/arch/msg/seat/rK1nDSewAbVL_weOp98knYZcg6s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/">https://mailarchive.ietf.org/arch/msg/seat/Wjuz0fIj8tjYocUmiZZXcSwwFHw/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/">https://mailarchive.ietf.org/arch/msg/seat/SYiV4KZNr20re6QkGmyWS3pPteA/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/">https://mailarchive.ietf.org/arch/msg/seat/ZYgxm1ibt6p4dL7xF1YNdl0XSpc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/">https://mailarchive.ietf.org/arch/msg/seat/6LKgOp22YRxGTYb-i-BxiMGzMW4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/">https://mailarchive.ietf.org/arch/msg/seat/3oHcKPtXLfBUYCZoN1nnO6e1F-s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/">https://mailarchive.ietf.org/arch/msg/seat/aSybH9ihnNjN7SjdhhY_XtxhMtc/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/">https://mailarchive.ietf.org/arch/msg/seat/d_G8r7LMGjA45BPexZwsfmmAtJY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/">https://mailarchive.ietf.org/arch/msg/seat/u-za86_YJ0spwBXBwTVQzwiOCrU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/">https://mailarchive.ietf.org/arch/msg/seat/P4IMdvCx8lSEKrCiJIjbpBCRr4g/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/">https://mailarchive.ietf.org/arch/msg/seat/-AO9yFJoflV1wDwwch45dmqkmyo/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/">https://mailarchive.ietf.org/arch/msg/seat/H0LqHfBasQml69Y-9Zl_njfsE8s/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/">https://mailarchive.ietf.org/arch/msg/seat/3hOGlYyc_yntmvT0tjYxldlwaxM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/">https://mailarchive.ietf.org/arch/msg/seat/JbwL9cdl6fiP0vBGgASUUDmaPy8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/">https://mailarchive.ietf.org/arch/msg/seat/TtewHbMGKBQOKD2sqrgTrnpCOkI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/">https://mailarchive.ietf.org/arch/msg/seat/UsIj6o7wf4hX_uCL51TCTv-wFxU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/">https://mailarchive.ietf.org/arch/msg/seat/a6c8D6PBDRe0x4DAqXM3t4EPc4c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/">https://mailarchive.ietf.org/arch/msg/seat/prB537Jht2kELVCSrTRktjbp7Y4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/">https://mailarchive.ietf.org/arch/msg/seat/RPnKYfUCD_MRw3hnA00zg684yGM/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/">https://mailarchive.ietf.org/arch/msg/seat/nMH_0sLLU5MekoEnzWKJnIJmaSk/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/">https://mailarchive.ietf.org/arch/msg/seat/GJCA31mgAehlgFPRu_yHA10lKPI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/">https://mailarchive.ietf.org/arch/msg/seat/9f-21JMK6s1Pdcob6mPo06rNwmQ/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/">https://mailarchive.ietf.org/arch/msg/seat/8qq_GFT391IEbGZZQUtYMONX9U0/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/">https://mailarchive.ietf.org/arch/msg/seat/xzu2UlClYMkG8gNSOClxGJgwnOI/</eref></t>
          </li>
          <li>
            <t>Exploit: <eref target="https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/">https://mailarchive.ietf.org/arch/msg/seat/MfxWpRtlTqPElX8vX4v8uiN65TU/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/">https://mailarchive.ietf.org/arch/msg/seat/PkU0jW_xHAF18rZmtZJ2A2p_wHs/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/">https://mailarchive.ietf.org/arch/msg/seat/jZmdYKQlfherbhowIEmZRw2HF1c/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/">https://mailarchive.ietf.org/arch/msg/seat/-0j6UpsD_CebqPPMNkDJCjySqEI/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/">https://mailarchive.ietf.org/arch/msg/rats/ssDrZRFW4s6CSaYeA9ImH0PPQ10/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/">https://mailarchive.ietf.org/arch/msg/rats/OPBI_Wd-RoTzzdh5D0JZoWlNGI8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/">https://mailarchive.ietf.org/arch/msg/rats/nfrdr1T9Pdp6D_kj2Et3XZk-hOY/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/">https://mailarchive.ietf.org/arch/msg/rats/gMMvtP1IXsXFfb0X5nMhRTaLLok/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/">https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/">https://mailarchive.ietf.org/arch/msg/rats/DaA1jDQNF-bdO5x-dkVbSzlHcD4/</eref></t>
          </li>
          <li>
            <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/">https://mailarchive.ietf.org/arch/msg/rats/ptkHZUDzSoYnD6R5zln6HcE1cv4/</eref></t>
          </li>
        </ul>
        <section anchor="main-questions">
          <name>Main Questions</name>
          <t>In short, five main questions have been raised by WG participants in support of our work:</t>
          <ul spacing="normal">
            <li>
              <t>What <strong>security property</strong> hybrid (intra- + post-handshake attestation) provides that post-handshake attestation alone cannot provide?</t>
            </li>
            <li>
              <t>Since continuous attestation is required in most use cases <xref target="CSA-eBPF"/> <xref target="MITRE-Continuous-Attestation"/>, how is <strong>additional complexity</strong> of <strong>intra</strong>-handshake attestation justified? Use cases with one-time attestation can be covered by doing attestation round immediately after Connection Establishment Time: see <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-6-2">reference</eref>.</t>
            </li>
            <li>
              <t>What is the benefit of doing <strong>signatures</strong> of remote attestation <strong>within</strong> the handshake (as this latency can be exploited)? We add that <strong>verification</strong> of signatures is also time consuming, which can be exploited too. See <eref target="https://www.ietf.org/archive/id/draft-usama-seat-intra-vs-post-04.html#section-4.2.4">reference</eref>.</t>
            </li>
            <li>
              <t>How evidence is bound to the secure channel without involving any <strong>shared secret</strong>? See <xref target="TLS-RA"/>.</t>
            </li>
            <li>
              <t>How does a verifying relying party get the legitimate PIIDs and CHIP_IDs?</t>
            </li>
          </ul>
        </section>
        <section anchor="guidance-text">
          <name>Guidance Text</name>
          <ul spacing="normal">
            <li>
              <t>Evidence MUST be bound to the secure channel. Failure to do so results in
relay attacks <xref target="CVE-2026-33697"/>, <xref target="EUVD-2026-16488"/>, <xref target="GHSA-Cocos-AI"/>.</t>
            </li>
            <li>
              <t>Verifier MUST have access to legitimate hardware identifiers of the
Attester. Failure to do so results in relay attacks <xref target="GHSA-Edgeless-Systems"/>.</t>
            </li>
            <li>
              <t>Verifier MUST carefully check the binding. Failure to do so results in
relay attacks <xref target="GHSA-Cocos-AI2"/>, <xref target="GHSA-Cocos-AI3"/>.</t>
            </li>
            <li>
              <t>Binder MUST contain shared secrets. Failure to do so results in relay
attacks <xref target="GHSA-Privasys-rustls"/>, <xref target="GHSA-Privasys-go"/>, <xref target="GHSA-Privasys-eov"/>, <xref target="GHSA-Privasys-eom"/>, <xref target="GHSA-Privasys-rtc"/>, <xref target="GHSA-Privasys-rtc-da"/>, <xref target="GHSA-Privasys-rtc-tcu"/>.</t>
            </li>
          </ul>
        </section>
      </section>
      <section anchor="researchers-outside-of-ietfirtf">
        <name>Researchers outside of IETF/IRTF</name>
        <t>Some researchers have approached us confirming the proof-of-concept of the vulnerabilities in intra-handshake attestation. More information will be added once their pre-prints/papers are public.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>All of this document is about the <strong>insecurity</strong> of <strong>intra</strong>-handshake (aka early) attestation.</t>
      <t>By no means should the vendors mentioned in this draft be considered less secure than any other vendors implementing intra-handshake attestation solutions. In particular, those who have closed-source implementations are most likely more vulnerable than the open-source ones, since the former cannot easily be reviewed by the security community. Even extensive security reviews -- of closed-source implementations -- by cybersecurity firms often do not perform formal analysis, and thus such reviews may miss corner cases and subtle vulnerabilities.</t>
    </section>
    <section anchor="ethical-considerations">
      <name>Ethical Considerations</name>
      <t>We (i.e., the super set of all authors involved in this research, including but not limited to Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura, Viacheslav Dubeyko, Jean-Marie Jacquet, Songbo Bu, Chengxin Huang, Haowen Song, Kaya Ercihan, Massimiliano Brighindi, and Iman Schrock) are ethical researchers aiming to protect the community from the potential harm caused by the exploitability of the vulnerabilities in intra-handshake attestation. We have responsibly disclosed the vulnerabilities to the respective developers and maintainers following their respective disclosure processes and provided them our proposed mitigations and requested them to take rapid action.</t>
      <t>We have released only the formal analysis for published CVE-2026-33697. To minimize exploit in the wild, we have not publicly released the proof-of-concept exploit code.</t>
      <t>We have not retrieved any real data from any real system. We have not released any key to any public forum or to any person.</t>
      <section anchor="evidence-of-explanation-of-vulnerabilities-to-the-authors-of-vulnerable-drafts">
        <name>Evidence of Explanation of Vulnerabilities to the Authors of Vulnerable Drafts</name>
        <t>To the best of our abilities, knowledge, and understanding, we have tried to explain the vulnerabilities to the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> first privately in several meetings and then later on publicly for at least half a year at several forums, including but not limited to CCC Attestation SIG and IETF/IRTF. Please see the (non-exhaustive list of) recordings <xref target="sec-recordings"/> and the archives <xref target="sec-archives"/> below. We sincerely thank the authors of <xref target="I-D.fossati-tls-attestation-10"/> for withdrawing their draft to protect further exploits mentioned in <xref target="sec-news"/>.</t>
        <section anchor="sec-recordings">
          <name>Recordings</name>
          <table>
            <name>Evidence of several explanations of vulnerabilities to the authors of vulnerable drafts</name>
            <thead>
              <tr>
                <th align="left">Event/Host</th>
                <th align="left">Venue</th>
                <th align="left">Date(s)</th>
                <th align="left">Evidence</th>
              </tr>
            </thead>
            <tbody>
              <tr>
                <td align="left">System Boot and Security MC @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2585/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">BoF @ <eref target="https://lpc.events/event/20/">Linux Plumbers Conference 2026</eref></td>
                <td align="left">Prague, Czechia</td>
                <td align="left">5 Oct, 2026</td>
                <td align="left">
                  <eref target="https://lpc.events/event/20/contributions/2640/">abstract</eref>, slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/event/14th-plenary/">GA4GH 14th Plenary Meeting</eref></td>
                <td align="left">Singapore</td>
                <td align="left">28 Sept-2 Oct, 2026</td>
                <td align="left">slides, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/16th-privacy-enhancing-techniques-convention">PET-CON 2026.2: 16th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Lübeck, Germany</td>
                <td align="left">28-29 Sept, 2026</td>
                <td align="left">slides</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sites.google.com/di.uniroma1.it/esorics2026/">ESORICS 2026</eref></td>
                <td align="left">Rome, Italy</td>
                <td align="left">14-18 Sept, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/414416257_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">slides</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">14 Sept, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">slides</eref>, <eref target="https://youtu.be/y5_SR0-DzH0?t=255">video</eref></td>
              </tr>
              <tr>
                <td align="left">Hackathon @ <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">4 September, 2026</td>
                <td align="left">
                  <eref target="https://notes.inria.fr/2ppogr2fTSKusRog3RXbPQ?view#topic-security-analysis-of-attested-tls-and-attested-edhoc">topic synopsis</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/">RIOT Summit 2026</eref></td>
                <td align="left">Grenoble, France</td>
                <td align="left">2-4 September, 2026</td>
                <td align="left">
                  <eref target="https://summit.riot-os.org/2026/blog/speakers/muhammad-usama-sardar/">abstract</eref>, <eref target="https://www.researchgate.net/publication/413988306_Security_Analysis_of_Attested_TLS_and_Attested_EDHOC">slides</eref>, video</td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ga4gh.org/work_stream/data-security/">Data Security Work Stream (DSWS)</eref> at the <eref target="https://www.ga4gh.org/">Global Alliance for Genomics and Health (GA4GH)</eref></td>
                <td align="left">Virtual</td>
                <td align="left">24 Aug, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/413569575_High-Severity_Vulnerabilities_in_Former_GIF_Design_for_Attested_TLS_draft-fossati-seat-early-attestation">slides</eref>, <eref target="https://us02web.zoom.us/rec/share/UAn381deia-aMNmjGHhMqxocc1HcyF7ksLlaeeKefxO4bSC2mHPzwPQPYGe2dnZR.zfleYCmmtiteo_NS">video</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential AI Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/odgd_xmhjQXiR_aLYdqtVvDJeF4/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">21 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-seat-binding-properties-of-expat-00.pdf">slides</eref>, <eref target="https://youtu.be/Fb5Hzh1mp1E?t=4189">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">IETF 126 Hackdemo Happy Hour</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://wiki.ietf.org/en/meeting/126/hackathon/hackdemo">demo</eref></td>
              </tr>
              <tr>
                <td align="left">Confidential Computing Public Side Meeting @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">20 July, 2026</td>
                <td align="left">
                  <eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">plan</eref>, <eref target="https://www.researchgate.net/publication/410954219_Proposed_RG_Confidential_Computing_for_Agentic_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hotrfc-sessa-15-confidential-computing-and-digital-sovereignty-00">slides</eref>, <eref target="https://youtu.be/FDHWRijxKso?t=3285">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/126-hackathon/">IETF 126 Hackathon</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/126/hackathon#cve-2026-33697-cvss-75-intra-handshakefail">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-hackathon-sessd-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/GRqyrDIEgEw?t=1340">video</eref></td>
              </tr>
              <tr>
                <td align="left">IEPG @ <eref target="https://www.ietf.org/meeting/126/">IETF 126</eref></td>
                <td align="left">Vienna, Austria</td>
                <td align="left">19 July, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00">slides</eref>, <eref target="https://youtu.be/g8q_u19vXzk?t=4404">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">Workshop</eref> @ <eref target="https://www.wissenschaftsnacht-dresden.de/en/">Dresden Science Night 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">26 June, 2026</td>
                <td align="left">
                  <eref target="https://www.wissenschaftsnacht-dresden.de/programm/detailansicht/confidential-computing-15585">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://output-dd.de/">Output 2026</eref></td>
                <td align="left">Dresden</td>
                <td align="left">25 June, 2026</td>
                <td align="left">
                  <eref target="https://output-dd.de/projekte/relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems/">demo</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit 2026</eref> (presented by Jens Albers)</td>
                <td align="left">San Francisco, USA</td>
                <td align="left">23-24 June, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411851358_Standardization_of_Attested_TLS">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://confidentialcontainers.org/">Confidential Containers Community Meeting</eref> @ <eref target="https://www.cncf.io/">Cloud Native Computing Foundation</eref></td>
                <td align="left">Virtual</td>
                <td align="left">30 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849492_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref>, <eref target="https://zoom.us/rec/share/3thZhsRi-BZJL-GqjnwGzh7inbltuKIlpVjqMlWp6WRdMTZ66Z8p-8YjaaeOfbhX.CoH6YBukaKua0gkt">video</eref> around timestamp 00:27:00</td>
              </tr>
              <tr>
                <td align="left">GIF Project showcase @ <eref target="https://www.ga4gh.org/event/april-connect-2026/">GA4GH April Connect 2026</eref></td>
                <td align="left">Montreal, Canada (virtual)</td>
                <td align="left">17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/412136610_Trusted_Research_Environment_TRE_Open_Suite">slides</eref>, <eref target="https://youtu.be/Kr9oxp1fdn0?t=1083">video</eref>, <eref target="https://www.ga4gh.org/document/arpril-connect-2026-meeting-report/">report</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/">NSA Symposium on Hot Topics in the Science of Security (HotSoS) 2026</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 April, 2026</td>
                <td align="left">
                  <eref target="https://sos-vo.org/group/hotsos/2026/sardar">abstract</eref>, <eref target="https://sos-vo.org/system/files/2026-04/20260416_HotSoS%20%281%29.pdf">slides</eref>, <eref target="https://sos-vo.org/group/hotsos/2026/sardar">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fg-pet.gi.de/veranstaltung/15th-privacy-enhancing-techniques-convention">PET-CON 2026.1: 15th Privacy Enhancing Techniques Convention</eref></td>
                <td align="left">Karlsruhe, Germany</td>
                <td align="left">16-17 April, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411849502_Formal_Analysis_of_Attested_TLS">slides</eref>, <eref target="https://www.researchgate.net/publication/411852738_Formal_Analysis_of_Attested_TLS_and_Standardization_in_the_IETF">poster</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://gtmfs2026.sciencesconf.org/program?lang=en">GTMFS 2026: Annual Meeting of the WG "Formal Methods in Security"</eref></td>
                <td align="left">Luz-Saint-Sauveur, France</td>
                <td align="left">24-26 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/411853715_Relay_Attacks_in_Intra-handshake_Attestation">slides</eref></td>
              </tr>
              <tr>
                <td align="left">CFRG @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">19 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-cfrg-relay-attacks-00">slides</eref>, <eref target="https://youtu.be/IfKgbO74Lt4?t=6054">video</eref></td>
              </tr>
              <tr>
                <td align="left">SEAT @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref> (relay)</td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">17 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-seat-security-analysis-00">slides</eref>, <eref target="https://youtu.be/hX7genEkN7w?t=676">video</eref></td>
              </tr>
              <tr>
                <td align="left">Side meeting @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://www.researchgate.net/publication/403474373_Proposed_RG_Confidential_AI">slides</eref></td>
              </tr>
              <tr>
                <td align="left">LAKE @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">16 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-lake-formal-analysis-of-attested-edhoc-00">slides</eref>, <eref target="https://youtu.be/JzfLpbnhl0A?t=3117">video</eref></td>
              </tr>
              <tr>
                <td align="left">HotRFC @ <eref target="https://www.ietf.org/meeting/125/">IETF 125</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hotrfc-sessa-formal-proof-of-insecurity-of-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/OtOo7Nogisw?t=3514">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://www.ietf.org/meeting/hackathons/125-hackathon/">IETF 125 Hackathon</eref></td>
                <td align="left">Shenzhen, China (virtual)</td>
                <td align="left">14-15 Mar, 2026</td>
                <td align="left">
                  <eref target="https://wiki.ietf.org/en/meeting/125/hackathon#relay-attacks-in-intra-handshake-attestation-for-confidential-agentic-ai-systems">Hackathon project</eref>, <eref target="https://datatracker.ietf.org/meeting/125/materials/slides-125-hackathon-sessd-relay-attacks-in-intra-handshake-attestation-00">slides</eref>, <eref target="https://youtu.be/62A58qH19MI?t=2270">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">10 Feb, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksGen_20260210.pdf">slides</eref>; <eref target="https://www.youtube.com/watch?v=idqwb0hFlhs&amp;list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1061s">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/session/rats">IETF RATS Interim meeting</eref></td>
                <td align="left">Virtual</td>
                <td align="left">9 Feb, 2026</td>
                <td align="left">
                  <eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-01/materials/slides-interim-2026-rats-01-sessa-relayattacks-00.pdf">slides</eref>, <eref target="https://youtu.be/gURY61dViPw?t=1474">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/track/confidential-computing/">Confidential Computing</eref> devroom at <eref target="https://fosdem.org/2026/">FOSDEM 2026</eref></td>
                <td align="left">Brussels, Belgium</td>
                <td align="left">31 Jan-1 Feb, 2026</td>
                <td align="left">
                  <eref target="https://fosdem.org/2026/schedule/event/GHGFBM-attestedtls/">abstract</eref>, <eref target="https://fosdem.org/2026/events/attachments/GHGFBM-attestedtls/slides/267432/20260201_60u9e0n.pdf">slides</eref>, <eref target="https://video.fosdem.org/2026/ud6215/GHGFBM-attestedtls.av1.webm">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">27 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacksProposal_20260127.pdf">slides</eref>; <eref target="https://youtu.be/P04tLJcSxfM?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=434">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">13 Jan, 2026</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_RelayAttacks_20260113.pdf">slides</eref>; <eref target="https://youtu.be/cSrCZNyo7_g?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=1083">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">16 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation/meetings/blob/main/materials/MuhammadUsamaSardar_Binding_Properties_20251216.pdf">slides</eref>; <eref target="https://youtu.be/w_MrjMeHyP8?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=593">video</eref></td>
              </tr>
              <tr>
                <td align="left">
                  <eref target="https://github.com/CCC-Attestation">CCC Attestation SIG</eref></td>
                <td align="left">Virtual</td>
                <td align="left">2 Dec, 2025</td>
                <td align="left">
                  <eref target="https://github.com/muhammad-usama-sardar/CCC-Att-meetings/blob/main/materials/MuhammadUsamaSardar_Open_Questions_20251202.pdf">slides</eref>; <eref target="https://youtu.be/16aGZ-oZidg?list=PLmfkUJc39uMhZsNGmpx-qD-uCoQyMglIp&amp;t=2920">video</eref></td>
              </tr>
            </tbody>
          </table>
        </section>
        <section anchor="sec-archives">
          <name>Archives</name>
          <t>Since January, we have publicly informed the authors of vulnerable drafts <xref target="I-D.fossati-tls-attestation-09"/>, <xref target="I-D.fossati-seat-early-attestation"/>, and <xref target="I-D.ritz-seat-facts"/> and shared our results with the community for review and to raise awareness on high-severity vulnerabilities and apply appropriate mitigations for the safety of their users:</t>
          <section anchor="intra-handshakefail-1">
            <name>Intra-handshake.fail</name>
            <section anchor="ietfhttpswwwietforg">
              <name><eref target="https://www.ietf.org/">IETF</eref></name>
              <ul spacing="normal">
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">SEAT WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/rats/6gbqx0XY8WYrH3Mx4vO8n2-uKgY/">RATS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/tls/8lyqHh9y7_Lv6b1iXhpUqYrp0M0/">TLS WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/lake/Tovtl7wgvzwJWT2I2ZwnhoIOnYQ/">LAKE WG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/saag/jBZVk7YySwpaFqydAfxW33kNZPY/">SAAG</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/practical-cybersecurity/d65WPaC0WbZRwxTBclnTkf7SmRs/">Practical Cybersecurity list</eref></t>
                </li>
                <li>
                  <t>Agent2agent list <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/ubz7uXCs--YzuSWyXNNsmWf_tSQ/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/agent2agent/xHhjA94fzed6ONIvPRgwTT-WRmA/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/dmsc/QC2adIcYkxiTlniEcc7ggk86BAY/">DSMC list</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/hackathon/PIrJ2O_QqcNUAnMIn_Vh22ImWMc/">Hackathon</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/126attendees/V9BKZJ_DGkZPdlnjBaUeyluhbqQ/">126attendees</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="irtfhttpswwwirtforg">
              <name><eref target="https://www.irtf.org/">IRTF</eref></name>
              <ul spacing="normal">
                <li>
                  <t>UFMRG: <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZWK0uMM92OdwlPbgXBvQApDpe5Q/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZRhR7o1HrWxfGDfgRJMR65RBkDE/">thread2</eref></t>
                </li>
                <li>
                  <t>CFRG <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/NbxHIw9H_xpSYbgfO_n7lVIFeWs/">thread1</eref> and <eref target="https://mailarchive.ietf.org/arch/msg/cfrg/U5YHd91lYjiqCTt9BZyVDNFeUpM/">thread2</eref></t>
                </li>
                <li>
                  <t><eref target="https://mailarchive.ietf.org/arch/msg/din/_8LE3Ru1xX16hgGJwryMTRwRoaA/">DINRG</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ccchttpsconfidentialcomputingio">
              <name><eref target="https://confidentialcomputing.io/">CCC</eref></name>
              <ul spacing="normal">
                <li>
                  <t>Attestation SIG: <eref target="https://lists.confidentialcomputing.io/g/attestation/topic/117207133">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/attestation/message/334">thread2</eref></t>
                </li>
                <li>
                  <t>TAC: <eref target="https://lists.confidentialcomputing.io/g/tac/topic/117932193">thread1</eref> and <eref target="https://lists.confidentialcomputing.io/g/tac/topic/120068850">thread2</eref></t>
                </li>
              </ul>
            </section>
            <section anchor="ocphttpswwwopencomputeorg">
              <name><eref target="https://www.opencompute.org/">OCP</eref></name>
              <ul spacing="normal">
                <li>
                  <t>OCP Security: <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/117932716">message1</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120069056">message2</eref>, <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120483814">message3</eref> and <eref target="https://ocp-all.groups.io/g/OCP-Security/topic/intra_handshake_fail/120524635">message4</eref></t>
                </li>
              </ul>
              <t>If you know any other relevant mailing list that we should inform for protection of users, please let us know.</t>
            </section>
          </section>
          <section anchor="earlyattestationbleed-1">
            <name>EarlyAttestationBleed</name>
            <ul spacing="normal">
              <li>
                <t><eref target="https://mailarchive.ietf.org/arch/msg/ufmrg/ZQKdp07P4UeTushAC1q9eBBtp0s/">IRTF UFMRG</eref></t>
              </li>
              <li>
                <t><eref target="https://datatracker.ietf.org/meeting/interim-2026-rats-03/materials/slides-interim-2026-rats-03-sessa-protecting-the-rats-ecosystem-from-critical-severity-vulnerabilities-00">IETF RATS</eref></t>
              </li>
              <li>
                <t><eref target="https://ocp-all.groups.io/g/OCP-Security/message/1263">OCP Security</eref></t>
              </li>
              <li>
                <t><eref target="https://sympa.inria.fr/sympa/arc/proverif/2026-09/msg00000.html">ProVerif</eref></t>
              </li>
            </ul>
          </section>
        </section>
      </section>
    </section>
    <section anchor="contributions">
      <name>Contributions</name>
      <t>Contributions to the draft are welcome at <eref target="https://github.com/muhammad-usama-sardar/intra-handshake-fail">https://github.com/muhammad-usama-sardar/intra-handshake-fail</eref>.</t>
      <t>Wenn Sie nur Deutsch sprechen, können Sie sich gerne per E-Mail an den Erstautor wenden. Wir haben Mitglieder, die Ihnen bei der Übersetzung Ihres Beitrags helfen können.</t>
      <t>如果您只会说中文，非常欢迎您通过电子邮件联系第四位作者。我们有成员可以协助翻译您的投稿。</t>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="Intra-handshake.fail" target="https://www.researchgate.net/publication/408219182_Intra-handshakefail_CVE-2026-33697_High-severity_CVE_in_Attested_TLS">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="June"/>
          </front>
        </reference>
        <reference anchor="Intra-handshake.fail-repo" target="https://github.com/muhammad-usama-sardar/intra-handshake.fail">
          <front>
            <title>Intra-handshake.fail (CVE-2026-33697): High-severity CVE in Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="V." surname="Dubeyko">
              <organization/>
            </author>
            <author initials="J.-M." surname="Jacquet">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-33697" target="https://www.cve.org/CVERecord?id=CVE-2026-33697">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-16488" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-16488">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92701" target="https://www.cve.org/CVERecord?id=CVE-2026-92701">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="CVE-2026-92702" target="https://www.cve.org/CVERecord?id=CVE-2026-92702">
          <front>
            <title>Cocos AI Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author>
              <organization>CVE</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83194" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83194">
          <front>
            <title>EUVD-2026-83194</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="EUVD-2026-83192" target="https://euvd.enisa.europa.eu/enisa/EUVD-2026-83192">
          <front>
            <title>EUVD-2026-83192</title>
            <author>
              <organization>ENISA</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-vfgg-mvxx-mgg7">
          <front>
            <title>CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="March"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI2" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Cocos-AI3" target="https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw">
          <front>
            <title>Cocos AI intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path</title>
            <author initials="" surname="Ultraviolet Cocos AI">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h">
          <front>
            <title>Remote attestation is susceptible to relay attacks</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="GHSA-Edgeless-Systems2" target="https://github.com/edgelesssys/contrast/security/advisories/GHSA-m2qg-wrxv-h898">
          <front>
            <title>Generated policies don't detect all image substitutions</title>
            <author initials="" surname="Edgeless Systems">
              <organization/>
            </author>
            <date year="2026" month="August"/>
          </front>
        </reference>
        <reference anchor="SEAT-vulnerability-report" target="https://mailarchive.ietf.org/arch/msg/seat/x3eQxFjQFJLceae6l4_NgXnmsDY/">
          <front>
            <title>Relay Attacks in Intra-handshake Attestation for Confidential Agentic AI Systems</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <date year="2026" month="January"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rustls" target="https://github.com/Privasys/rustls/security/advisories/GHSA-j6qv-435v-r492">
          <front>
            <title>Privasys RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-go" target="https://github.com/Privasys/go/security/advisories/GHSA-7jfw-53rm-phh2">
          <front>
            <title>Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eov" target="https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9">
          <front>
            <title>enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-eom" target="https://github.com/Privasys/enclave-os-mini/security/advisories/GHSA-49qm-4pj3-w2c6">
          <front>
            <title>enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-5qrc-v874-mxvx">
          <front>
            <title>ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-da" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-pj2x-5wqv-fh57">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to Diversion Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="GHSA-Privasys-rtc-tcu" target="https://github.com/Privasys/ra-tls-clients/security/advisories/GHSA-gg8q-mfhh-wrrc">
          <front>
            <title>Privasys Intra-handshake attested TLS implementation is vulnerable to TOCTOU Attacks</title>
            <author initials="" surname="Privasys">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="ID-Crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author fullname="Muhammad Usama Sardar" initials="M." surname="Sardar">
              <organization>TU Dresden, Dresden, Germany</organization>
            </author>
            <author fullname="Mariam Moustafa" initials="M." surname="Moustafa">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <author fullname="Tuomas Aura" initials="T." surname="Aura">
              <organization>Aalto University, Espoo, Finland</organization>
            </author>
            <date month="June" year="2026"/>
          </front>
          <seriesInfo name="Proceedings of the ACM Asia Conference on Computer and Communications Security" value="pp. 547-560"/>
          <seriesInfo name="DOI" value="10.1145/3779208.3785387"/>
          <refcontent>ACM</refcontent>
        </reference>
        <reference anchor="ID-Crisis-repo" target="https://github.com/CCC-Attestation/formal-spec-id-crisis">
          <front>
            <title>Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="M." surname="Moustafa">
              <organization/>
            </author>
            <author initials="T." surname="Aura">
              <organization/>
            </author>
            <date year="2025" month="November"/>
          </front>
        </reference>
        <reference anchor="refTLS">
          <front>
            <title>Verified Models and Reference Implementations for the TLS 1.3 Standard Candidate</title>
            <author fullname="Karthikeyan Bhargavan" initials="K." surname="Bhargavan">
              <organization/>
            </author>
            <author fullname="Bruno Blanchet" initials="B." surname="Blanchet">
              <organization/>
            </author>
            <author fullname="Nadim Kobeissi" initials="N." surname="Kobeissi">
              <organization/>
            </author>
            <date month="May" year="2017"/>
          </front>
          <seriesInfo name="2017 IEEE Symposium on Security and Privacy (SP)" value="pp. 483-502"/>
          <seriesInfo name="DOI" value="10.1109/sp.2017.26"/>
          <refcontent>IEEE</refcontent>
        </reference>
        <reference anchor="TLS-RA" target="https://www.usenix.org/conference/atc25/presentation/weinhold">
          <front>
            <title>Separate but together: integrating remote attestation into TLS</title>
            <author initials="" surname="Carsten Weinhold">
              <organization/>
            </author>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Ionuț Mihalcea">
              <organization/>
            </author>
            <author initials="" surname="Yogesh Deshpande">
              <organization/>
            </author>
            <author initials="" surname="Hannes Tschofenig">
              <organization/>
            </author>
            <author initials="" surname="Yaron Sheffer">
              <organization/>
            </author>
            <author initials="" surname="Thomas Fossati">
              <organization/>
            </author>
            <author initials="" surname="Michael Roitzsch">
              <organization/>
            </author>
            <date year="2025" month="July"/>
          </front>
        </reference>
        <reference anchor="CSA-eBPF" target="https://cloudsecurityalliance.org/blog/2026/09/09/mitre-s-new-framework-securing-the-ebpf-layer-your-ai-depends-on">
          <front>
            <title>MITRE's New Framework: Securing the eBPF Layer Your AI Depends On</title>
            <author initials="" surname="Cloud Security Alliance">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="MITRE-Continuous-Attestation" target="https://www.mitre.org/news-insights/publication/framework-continuous-remote-attestation">
          <front>
            <title>Framework for Continuous Remote Attestation</title>
            <author initials="" surname="MITRE's Confidential Computing Layered Attestation Working Group">
              <organization/>
            </author>
            <date year="2026" month="July"/>
          </front>
        </reference>
        <reference anchor="EarlyAttestationBleed" target="https://www.researchgate.net/publication/414529199_EarlyAttestationBleed_Three_Critical-severity_Vulnerabilities_of_CVSS_90_in_Confidential_Computing">
          <front>
            <title>EarlyAttestationBleed: Three Critical-severity Vulnerabilities of CVSS ≥ 9.0 in Confidential Computing</title>
            <author initials="M. U." surname="Sardar">
              <organization/>
            </author>
            <author initials="" surname="Songbo Bu">
              <organization/>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="I-D.fossati-seat-early-attestation">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="20" month="September" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a TLS extension that
   enables the negotiation and binding of the TLS authentication key to
   a remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   This extension has been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-07"/>
        </reference>
        <reference anchor="I-D.fossati-seat-early-attestation-04">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <author fullname="Tirumaleswar Reddy.K" initials="T." surname="Reddy.K">
              <organization>Nokia</organization>
            </author>
            <date day="27" month="May" year="2026"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using remote attestation
   which is a process by which an entity produces Evidence about itself
   that another party can use to appraise whether that entity is found
   in a secure state.  This document describes a series of TLS
   extensions that enable the binding of the TLS authentication key to a
   remote attestation session.  This enables an entity capable of
   producing attestation Evidence, such as a confidential workload
   running in a Trusted Execution Environment (TEE), or an IoT device
   that is trying to authenticate itself to a network access point, to
   present a more comprehensive set of security metrics to its peer.
   These extensions have been designed to allow the peers to use any
   attestation technology, in any remote attestation topology, and to
   use them mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-seat-early-attestation-04"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-06">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="19" month="March" year="2024"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-06"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-09">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="30" month="April" year="2025"/>
            <abstract>
              <t>   The TLS handshake protocol allows authentication of one or both peers
   using static, long-term credentials.  In some cases, it is also
   desirable to ensure that the peer runtime environment is in a secure
   state.  Such an assurance can be achieved using attestation which is
   a process by which an entity produces evidence about itself that
   another party can use to appraise whether that entity is found in a
   secure state.  This document describes a series of protocol
   extensions to the TLS 1.3 handshake that enables the binding of the
   TLS authentication key to a remote attestation session.  This enables
   an entity capable of producing attestation evidence, such as a
   confidential workload running in a Trusted Execution Environment
   (TEE), or an IoT device that is trying to authenticate itself to a
   network access point, to present a more comprehensive set of security
   metrics to its peer.  These extensions have been designed to allow
   the peers to use any attestation technology, in any remote
   attestation topology, and mutually.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-09"/>
        </reference>
        <reference anchor="I-D.fossati-tls-attestation-10">
          <front>
            <title>Using Attestation in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)</title>
            <author fullname="Hannes Tschofenig" initials="H." surname="Tschofenig">
         </author>
            <author fullname="Yaron Sheffer" initials="Y." surname="Sheffer">
              <organization>Intuit</organization>
            </author>
            <author fullname="Paul Howard" initials="P." surname="Howard">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Ionuț Mihalcea" initials="I." surname="Mihalcea">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Yogesh Deshpande" initials="Y." surname="Deshpande">
              <organization>Arm Limited</organization>
            </author>
            <author fullname="Arto Niemi" initials="A." surname="Niemi">
              <organization>Huawei</organization>
            </author>
            <author fullname="Thomas Fossati" initials="T." surname="Fossati">
              <organization>Linaro</organization>
            </author>
            <date day="23" month="July" year="2026"/>
            <abstract>
              <t>   This draft has been withdrawn.

About This Document

   This note is to be removed before publishing as an RFC.

   Status information for this document may be found at
   https://datatracker.ietf.org/doc/draft-fossati-tls-attestation/.

   Source for this draft and an issue tracker can be found at
   https://github.com/yaronf/draft-tls-attestation.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-fossati-tls-attestation-10"/>
        </reference>
        <reference anchor="I-D.ritz-seat-facts">
          <front>
            <title>Factor-based Attestation and Credential Transport Scheme (FACTS) over TLS 1.3</title>
            <author fullname="Nathanael Ritz" initials="N." surname="Ritz">
              <organization>Independent</organization>
            </author>
            <date day="1" month="March" year="2026"/>
            <abstract>
              <t>   This document describes FACTS (Factor-based Attestation and
   Credential Transport Scheme) over TLS 1.3.  Conceptually acting as
   "multi-factor authentication" for machine identities, factor-based
   attestation derives session trust from multiple independent
   cryptographic inputs rather than a single point of failure.
   Specifically, it utilizes a dual-key scheme that binds identity to
   attestation evidence through the use of key encapsulation material
   keys (KEM) and traditional identity signing keys (IK), establishing
   per-session freshness.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ritz-seat-facts-00"/>
        </reference>
      </references>
    </references>
    <?line 1022?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Acknowledgment does not necessarily imply attestation. It implies that the authors found the feedback and discussion useful in improving the formal analysis, the corresponding paper, or this draft.</t>
      <t>This draft benefits from several years of research on attested TLS, in particular some of the recent works mentioned below:</t>
      <t><strong>EarlyAttestationBleed</strong> <xref target="EarlyAttestationBleed"/></t>
      <t>We wish to express our sincere appreciation to the following for their review:</t>
      <ul spacing="normal">
        <li>
          <t>Sammy Kerata Oina</t>
        </li>
        <li>
          <t>Drasko Draskovic</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Bertrand Foing</t>
        </li>
        <li>
          <t>Peg Jones</t>
        </li>
        <li>
          <t>Rebekah Overdorf</t>
        </li>
        <li>
          <t>Tobias Pulls</t>
        </li>
      </ul>
      <t><strong>Intra-handshake.fail</strong> <xref target="Intra-handshake.fail"/></t>
      <t>We gratefully acknowledge the following for insightful discussions and helpful reviews on <xref target="Intra-handshake.fail"/>:</t>
      <ul spacing="normal">
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Juho Forsén</t>
        </li>
        <li>
          <t>Markus Rudy</t>
        </li>
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Steve Kremer</t>
        </li>
        <li>
          <t>Tjaden Hess</t>
        </li>
        <li>
          <t>Martin Thomson</t>
        </li>
        <li>
          <t>Yuning Jiang</t>
        </li>
        <li>
          <t>Pavel Nikonorov</t>
        </li>
        <li>
          <t>Casey Wilson</t>
        </li>
        <li>
          <t>Anonymous ESORICS 2026 reviewers</t>
        </li>
        <li>
          <t>Marco Anisetti (ESORICS 2026 shepherd)</t>
        </li>
        <li>
          <t>Danko Miladinovic</t>
        </li>
        <li>
          <t>Rongkuan He</t>
        </li>
        <li>
          <t>Peeter Laud</t>
        </li>
        <li>
          <t>Stephen Holmes</t>
        </li>
        <li>
          <t>Ammara Gul</t>
        </li>
        <li>
          <t>Atul Prakash</t>
        </li>
        <li>
          <t>Paul Syverson</t>
        </li>
        <li>
          <t>Jan Tobias Muehlberg</t>
        </li>
        <li>
          <t>John Preuß Mattsson</t>
        </li>
        <li>
          <t>Britta Hale</t>
        </li>
        <li>
          <t>Werner Staub</t>
        </li>
        <li>
          <t>Songbo Bu</t>
        </li>
        <li>
          <t>Haowen Song</t>
        </li>
        <li>
          <t>Chengxin Huang</t>
        </li>
        <li>
          <t>Steve Luo</t>
        </li>
        <li>
          <t>Andrew Miller</t>
        </li>
        <li>
          <t>Kubilay Ahmet Küçük</t>
        </li>
        <li>
          <t>Iman Schrock</t>
        </li>
        <li>
          <t>Sophie Schmieg</t>
        </li>
        <li>
          <t>Davyd Okaianchenko</t>
        </li>
        <li>
          <t>Alistair Woodman</t>
        </li>
        <li>
          <t>Göran Selander</t>
        </li>
        <li>
          <t>Tom Sato</t>
        </li>
        <li>
          <t>Jakub Maria Plutowski</t>
        </li>
        <li>
          <t>Martin Friedrich</t>
        </li>
        <li>
          <t>Patrick Duggan</t>
        </li>
        <li>
          <t>Deb Cooley</t>
        </li>
      </ul>
      <t><strong>Identity Crisis</strong> <xref target="ID-Crisis"/></t>
      <t>We would like to thank our co-authors of paper <xref target="ID-Crisis"/> for their valuable contributions:</t>
      <ul spacing="normal">
        <li>
          <t>Mariam Moustafa</t>
        </li>
        <li>
          <t>Tuomas Aura</t>
        </li>
      </ul>
      <t>We also gratefully acknowledge the following for insightful discussions and helpful feedback:</t>
      <ul spacing="normal">
        <li>
          <t>Ionut Mihalcea</t>
        </li>
        <li>
          <t>Jean-Marie Jacquet</t>
        </li>
        <li>
          <t>Thomas Fossati</t>
        </li>
        <li>
          <t>Eric Rescorla</t>
        </li>
        <li>
          <t>Hannes Tschofenig</t>
        </li>
        <li>
          <t>Yaron Sheffer</t>
        </li>
        <li>
          <t>Laurence Lundblade</t>
        </li>
        <li>
          <t>Giridhar Mandyam</t>
        </li>
        <li>
          <t>Christopher Patton</t>
        </li>
        <li>
          <t>Jonathan Hoyland</t>
        </li>
        <li>
          <t>Richard Barnes</t>
        </li>
      </ul>
      <t><strong>refTLS</strong> <xref target="refTLS"/></t>
      <t>We sincerely thank the following for the foundational formal model of draft 20 of TLS 1.3 in their work <xref target="refTLS"/> that we have used as the foundation of all of this work:</t>
      <ul spacing="normal">
        <li>
          <t>Karthikeyan Bhargavan</t>
        </li>
        <li>
          <t>Bruno Blanchet</t>
        </li>
        <li>
          <t>Nadim Kobeissi</t>
        </li>
      </ul>
      <t><strong>General</strong></t>
      <t>Several others at the IETF, IRTF, CCC, and GA4GH have contributed by providing feedback over the years. A non-exhaustive list of contributors is <eref target="https://datatracker.ietf.org/meeting/126/materials/slides-126-iepg-sessa-05-intra-handshakefail-cve-2026-33697-00#page=17">here</eref>.</t>
      <t>Muhammad Usama Sardar is funded by German Research Foundation ("Deutsche Forschungsgemeinschaft.")</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA8y92XLjyJIo+K6vgFVZ35NSCyTBnXmmporiLokSRVJr2jUm
CARJiNiEhYtOVtu8zMM1uz8wNjOPY/MT/dYv8x39JeMeAYAAF0jIUmafOqcq
kwDCw8PDw8Pdw8Od5/kjR3FU8pn7pSFa6pqrOg6xHdFRDJ2rGbqtyMQiMndH
rDXXFi1t4qrcp9pdg89mskW+ki1lBM6YcLW7wYCrpIRTLvIue+BdLleslIJ3
pVThlBN1mcvBM2dGLPzQxteuyTkGR1YmkRzAgn4tZFIZeCEZmqJPj385Esdj
iyzeGoCH+y9HkuiQqWGtP3OKPjGOjmRD0kUNCCBb4sThFd2xRH4G2NgzcU74
iaiofF44st2xptg2QHXWJnzdaQybHPcrJ6q2AX0rukxMAv/RnV9OuV+IrDiG
pYgq/uhUz+APw4K/9YfNX450VxsT6/ORDJh8PpIAR6Lbrv2ZmwAwcgRDyR0B
YIuIn7lqv1E9WhrWfGoZrvmZGzSqw6M5WcMj+fMRx3PVDidOoVcbf3SiyHPi
hhb4mhFo62F0TiJP6OzuPMkeLYjuAua/cpyH1X0LfzDC3AOyMDFcC1/hYw0o
iJ/8QVaiZqokBTOHz0VLmn3mZo5j2p/T6dDLNIAD0Iozc8dAWs2diZomyrxr
i5rI26Ili1Z63zz9As1UEUcHzXzAe5unGPSUYuwFlD7MC6mZo0FHR6LrzAwL
pwA65ThgLZWx0S9dr0PuFjvkBrTDX+hXhjUVdeWV0v4zNyTSTFckUeVudWVB
LFtx1sj0dYvYwEi0hc/cw9vIYwk+/Rx9YriALTxsEUsT9bX3UAaMMoJQLtHf
hM2FT5IRJUmKkeQPx+VlBjAlkz3julNEaUZsVVxwdXdM1nNj36BqhkXuibgg
4Q5/wVbiHzJrhnP8y54Ozomo813RUgh3LkovLnH2dRCl1ZWouVaIJKHfPkHO
iDpVXC2CzzN2pWFXqWfW1R+ujk1TY7IPtYGhT8cGd+buw2gAHDKdiQrXckWd
q+qwDCcGTAIVQXSSDdWYroE0qVPu0pFTUfxqM0UXI9iNVZfIxlSH/v+Y4rND
FKvNiD5dKTrXhp6n+3DrbORSpAvRtVAIWG/30RaNJdE5pMBPGfwMOEUXsplC
ppDPx6N2Ia5FrmFJCuCwF7el4kizEHc8uZbiP/AxwI9eiaXCKo/gMQfgKcKA
/2FTSClptg+NusVduGNFFWHzmWnE4S7+49//4//9j3+fM5wU3calmuIuUlw1
Fbzcg2+9N1NU7noFBJRDfB5BS7ZSc1dy538Y9DNRdTVdSQGcvWxLrJmicFfK
3FBFGLk73yuHZoSriabigCRCflmFKFZ1bUfRT2EmV6IdJdztoBrBTN/0krJT
k/ipG6zVhQiMC4tTBQAW2Tt/yKQzw+EuxfFW5+eiKepRETOmoOK7bSxErpbi
uinuXsGv7dAUNVLRV+9YTQE6VwTVFuQhO4IUWYhSSkstGcQ/TMtwDD2l7ZUx
55TUXL0xGDSurhoDblDtXA0bV28sa5S4pmHBtsf1FXtOdR5XdUQfRTqNPRB1
WxRsWqIuRaW0TGxQRXRij2yYG4fof2i2foiUXRG0IU1RFVEHwWgpU1jJsrIP
2V67w193G61qCKGBiHOvE5k4oODJROWGFqhWRhTHDrBklP3NmWJoZCqmLPhE
0Uj8dHeVObHEGXfjwnDWOuFrhqrCZO/Dsi3as5pqiHMgrkS10YFjTCaAGXIf
PtySXKIuylHRpbHu/pgBKAlBHcKrAzs0N5BmliHtXZGNbueyU+V6yC6SoZ5i
76lIVw4RtT8IJb/pfZUSgfpHOhO+C9DPuG19MIUKzGcKx1f6930R0u+pTngM
xIHp5W0CAgn3XXgNS8bTtEG3Hl4O2CioRsuduzrhsPkp60q0psTZaHrL5TIF
65qg/jeFBimdOGnTHaugCuHw0/lMOStUhHJ2tIUdIjeK4jaKYIYvR4o+8jEb
AWZMjfK1NfoPzxY8LPXblKefRd/cpXwVJ/r8nIc2nm5ygLy8RUzjZ9AYNPnD
NPbUW1Sm36U+U5x+IKWig/WgR7uia+AzfskeeNSrGTVj4NksjAycYnMLV9Vh
qY1VgvahRXDvhW9EaQ7vFBEsRhgeNRmJOSMafKrSpmA52R74PVwpLQjupGnA
oU8k2F1/V+Tftu2jzRxki1wXmZjOA7xo3N7V2adCMV8ux42ycdXxds+fPU7i
LuQU0RUblBvXMkz8I01/p7fwjxtq1ERMNp+SYaPVut9W9YeOtqAGuxvTI3co
YRNqivNgko9x2wF70ycLaEUIG3eU+gOHq2miEIszRWf2vTPv2cEbcghlbkBM
Zy81sj+cGhJsHqIkIQKNhQI6gEQ40E9nnK7AVkE001lTd4OhKQ6CQIlkOXXR
EVGigKLCVbt1btC44wdXvb9MmGwMYTYcVc4JlXyyFbHV+C+wc6j9O9CMncC3
0Mz+RTTjqNlqD6o85Ri+2oluMR8vPcKbTTYXXf2x+w3onpa4UAyVOJadlhDd
tE0kF3e1tCgvFNsAs9tO09EsJtMpry1WK16bTkuHN6DbDdBgzWxTJLtNEm9p
KT9f0ISJJxTBiJqCbv/x1Mubqxy/fM6u+NUq/xepl/sA6n28YPpZhLSKwIZm
vsw/Z63l9xGyIU+JCtzCD9ZAH82O0rNPNMOJOGSR12zXRmop+1ZoeOgJxk08
NOw1jhonz3YOD3z2PJX4Z6mw4CfL0uzwwP3Bcd7gDg16aw22CC4lnGrTAPUe
uuVkQ/+bAwafQySHE1UVeEicEqDEGKxfx0XK/Jyha9mXKb+0Vgt+Vq6UEw0d
nfC8LyfABHPWPGPl7TmnLiFPXCj6ziYfPqpAaQKm+wSXjaOAIK6iV1+RcA16
PUcWgwDatR5jAaCdiDIbLMGUQpwJ3cXxQVqzp0AV0UmvcuRm1Xy+aZ5fSkQk
RTU/upo+6Jpdf0y/2xagtOxZykIEsvMWzJW6xfr+S65f5VFoSDOYdqLDpGuG
TDhZkTndcDgUr5H1QXwRAisDZQO29cRxmBI5ukcSPFJ5F5f46KQZrocZ5Ln4
suDzOVgbVt7bl/cSxAe4Q4ypcYAQLQOne/75n40iU+MwNUrPkyVfyFkab85m
30MNYiyi5ICRqOKC8LD9LBTLcUV1D0EkYjmwr+Khnc0tiUUYZQwXSPODqLCL
12GqmIWJyU8r+Sn8R6t8F1W0g1TRFF35pyMJIhWzkVZeNFBLnkEtyUrF76CH
5UhReoDAhFXKS6qCh5x7yBEoXkzzgL3mxTWQND+cKlHUDhOl8GJJ/KJcyvPa
arH6PqLwsnhAmPwlO7rOzhgM3d+mwoQp/mjCmKi6FpYgZiezQoz+GksYR3J/
BGWG17Xh9e1/CVmm0/ILr01mM1BPLOldZOnU+Zql2AqeNF13UkImJQj5QjpX
KlWymXIqVyoXcvQMOPhwn5+Sqh7oe6RfoMYS0UhqhmaCgqaDGdxELzPoKLqo
rvFTY3LQU3llLAJaFd70VtZqNT6kFqXpWaLK2yaReEXmJYrZ9zgq4U3XgB1f
nIjRF8MU6JgWPrTIBHAPUTBTSQ96qWxGKKXoNMNbvl+NEg14QaSHL2PXAb6Z
0oMgjC1xyBSeo8Fo7dH9dWSx/S7dA0RCb4xrE11ZUVUOFNwJyH7QBtKiI2UL
aRN96h47p5dE0WeGKh+mVE20YLZ07j785Tvo2DF09//7P7muAgIYtMboy0cY
vz3j6vAfE5Ydib5ti3i2xA1taWZMYCDTrcaiBZQZzMgEBrY1RzNDE23gOtuG
8W2hqsBeAEZ431CcV5ue7tZgEZGzXjM6U93OsN/4m81dkSUefmlkSXWwAV2G
ME24RWAr7lJcA7s+Gq6FynedHrTZ3HVk06i8RwhIquHK/jKH/UrBEzc6e2PV
mKaxXRp4DP4PBrFFeJvXyZKf+LjxtocaD6jxZGxOeBVR49eAGi8qPDsDtHlD
j5lnxMEbJCztqocFfETpAfY/LG7dhaURXndRygXU8q0UrwXnWbWhhlsGe3BM
cZCl6cgpTWDsNg84K9MZSMfwgdCGItIGW7aq+Eg000Gx4E39fnHGJhwkV9ge
i4YxcSx2KvTBmUqIHCXT/k+AeS1CUKY6GOuzOeG5CxmQaBn70XD/+T/+H66S
yhwWvxHXnLDFiN975gbbRbYiVCqjvaMY0UGMdgYx2hrEyJiMcBCjSgbP4cL4
jwL8v0d8BwE4R0dHih9h4h1y8vXUhEkGHu1anuAIwozxvq/4TH77Q9yuI18U
3/yi8tYXQsb/Agj4ynCZiBLotkepVOroiOd5Thzb1DN7dISxGTQYjRMVzUbF
xLQMNAM5J4gek4kDxj5loH/8I3pc9eefp/Bs62CHPYyebmx/SF3mez7M7vsQ
HtIDc8oVgFBLcdruOCR0AgWH+4Qajn3MLWcgtoOxUO+PyNh8M67A3IWBzYwl
R7bDF7kJHTcsFBOppUjkFBrBpnZygm5HA3Zkcwb6CQJD68C2T058Y0AmtoJr
XhOlmaIT1A4sMFGJdcrZCna6ETXbXrsp9WqpgItFXlwKBajk7TlAin/8I060
IgF3RyLKsMWcnLiwQyKeorUGBFBFXQEBT05SNEgHVrCrOjaGhnJjUEuh4/Ga
jsZf29D3vtNmNmlMffEmcN8q96YRAYpoYyJXHoBI1Uf4HmiPEMA0nNBdCtpx
TGcDUJ5y6BgYwtCzjDs01U45MMlAWFVNDCfksyDpQAoR3SZ0dwG4liG7ksIc
a6d4SAEvg5+IoAWcQZbs7zOwS7kxIeh5nuvGUkUvYIguKlkAYyGSc4J6Dpg7
Ka7mWqA6OSrAQ3WNUIqenDhLI4g83gQtGzqhp/GRaGV8iKyMT0FY8xiUHH3q
fVs+pctCp8/t0Is8w3+nSTGV46hktmcwDnEqgvxz6GDGliEi5Xa5R0LGpWcT
qspRHYH2RDUaybCp+9CLpaaTa5q+4A+xFmMgUzRpa+qPtxllJJ9cHFFoeDab
wU1INDr1xwQRAC0U9GFAHOdy8wHrZMNUDDkA73WHAVIAgQMGw8b00AAxhTWg
uTrKkA9imhRYhRxqdj53nnp8ogGdcQBRu5BiuktvENHbbmGqFqHHmXbWBZH8
N3p+Ap8y4CH70pPymiLLKjk6+pVaqog/1WIOLWHO0/Bh/fsiCGcSmAKmDWaW
juiV0PFsn9p8EuciG8dxZCDQ2jRsUQUyWGQK+y4dEox5OaOGDAJbUx7AKfEO
aWzJMKlQRj84emIsB76EadANJwWqtaEBhr7ay+H8Yvg+7NZsgXiMOQfAMpEU
mwlyyTGAD1Ba4LQD4opMrSrv0E2DXUHUFVsD9cDQ9jy3w1jux5AuNxwV+5Zi
G2VLfCwu0HOOXgAAFC/8/gJPUmQmrkWJ7C8+4IsqiCEm+CkPWiD72RpBVHzb
PcwLdLZ9w10KDHd4z9M+9p/f0dlno9+W1vD/bRJEfAYJx02RiAwdR6mzax6R
kXrjhIWxkTc7ggbewkeIMy4DVCENdzrbGYTHY7jJT2G9m2wtK3osOWAl/spd
gyRFQXH0jnXobMiHLM6csnQ3R8f9Fi4xPM3Okv3H8VgywQrKEqjIshcwSJ9F
vFt+TCAolUffuCsjxX3jzra7hWe3NkEWgb9Vg0XwDVoI2KBGHVX/+b/9HzaF
qRuoFn0Djfwb9wWRJZbw3z/9pYizNNh+BI+q9LQH8Jh2n93qPjz+PWhkPxqN
LEMjh2iwSzNkhed7wIuRjnMf3XGOdZzHjgfAiMSi42eWGhWZkf7zH91/nvVf
oPQ3NHjIiA48/GuWsvWvuSgKhY9GocBQKMagkMfuD27AexHa9itqhKApaqMn
Zsy6B4uS4JUtO90Vrblr9115nfLPkcGEQ9etJIVtuZQpT47/zn0JgiUWmVQ5
FeJGNLtt3eYVBw8bi1OKytKkbgzg7bRrqqDS2egJKqSFbPqe4HAtvooHt3hC
js6fIbbla9dXzU69cTXsVC+LLa9n6LpWi7gtBp3We8Z/DMqJKBv0uARkxTMe
xn+JkTp7YW5RI+1LIGrymoaEpNkoQq4p00gAlJQbcKKS0uATCo/CkWCTsUFB
k0jaRP82mBaAINpE1BHmG4f8EglEd4zjDTMWP5oZi4wZS3uZ8RQWw+mGI2G/
iHUdwM4RIFr6aERLiOg/PjNf1G+/7Mh6UPC2NVtE3DfKNjrQL38eHf3bv/3b
0T0JrHPR3+TgAQwc/g8mia/ewS80OqhZMQYzZLPPHe3Z52jbw3uba3uO2KMd
oxKNyBC6uuzproiepjjKdLMTYntZsalRhAzno7qI+qpS3LWLWyksczQOCKx8
aCo6nOJwmrg+oueHQAWYUD9AB30F8CU0sgy0tjZ2FA+DmsD+z30Cg5OoXO44
GD4bVNywRdVAD8RwBtoCxlBBr7DfqAZwuHzEdKpQYNApKueoqOreE9iVNACJ
ChE7W/KDsMRNyMDRhKnlsjKhxwbOxvExYEah1xT69wZuuxYJCAISSwchYR8B
FRRQEnz3iU03qRRlmSNkGli9Jt66HcOmiZOgGqhiYAeRgJm3tBx0gtEjXKaf
/OMfkWA1dDzYtgvv4DvPqAUbWwYT4tRzLTFfCWu9xy0WtuaZ4tc1ZKLiTF1T
1dRfQd2AeZkzLmosvLgwR9wE3TTIIjhXmiFHFUEcFEKCHjfUjxv7nnUzXnM2
rt81GjP6FN8iV0GXX0FGOOJXDk+hQJIC5p6VVvNYAS+y0EniPDmKnN+knhDu
izidot3nkI+TRwHIY+pCQ/cFlRCeeSqH1668b6wHzS6YNRqRqeJuhfGr6B3w
x+jq3q+UN4ET5uzxkaCmp6+l7zErKQ/QwC6q8IU3y7AXNirk9zuSKXfSxcfM
HrZf4JygRBVxZYTOmj8h9mi3QgdL/XhvP7s+ZOgjcJLASFVjSSXn0uCor4Fy
CUgEb9X78ntjioNdADr+Gd07uBksNepC8/boI9C/r6nNhI0M0D72M6qJgjlo
LMqy5/exoscylHyeTcex7cqb5PeQUja8WA4ThTRAiMYxi7bnwlPwK7CePRcS
SH2LOGA9e8uB9UvdP4CoQvH3JMeOBXyYAdGZR0KuVGZ5WVNXowbhcrbmIv1T
rAKPLvXe7xkEMF/vDSrDhrS/7Sk7eJ4RNsyTE390MKKwB/mtrRcQdfVnvII4
UYjMlkNjBVsncgs3cEEOWHS393yn3AAauiAUB/55FkAYi7imAdqXq85gCKvL
sRTJ3sgWfSGnYLU5qamxSOMa4L1P0tLCto9hL5IMix2FCTmQpBbx3KYAe01Q
CcCNCY++FUvzRInvOmTsh9f/PRGIviTqbQOiNGGa0Ia1iHdofsq1gdmcMbq9
uSUwkb8ZnJyk0GSmP9EG8wYHRjTN2oCo9QLvLENu/zvqSAblkef5yL8A3HcY
o1LpnajBXwVmWNH3QvRVlv1LNdEy/B2vikVaAOLRx4L3OL95XAq+RhfzN9jZ
ZMXVQmA26mN0FGk2TGT1d/oVUYn8dZtOeIfExk5+hbXBw+qQUZH4E6mN7/E1
FxC+SZfrDgGPvu1RBXyq7E28cMrt5i1gSvtuugGOwd/RFXz6flQHO+dxH97D
3uBsr5/8oX64PeTN0kaMIfc3ogqGfzq7D0Tu+0HshJd7oILlwyx1Dk31v3Oh
HCywxYLKtIFJffJvjXkrivktcn3vtITig394F8RY/IQ+tB/eh+VIP6MPXhaT
LJLtOETa1hOuMW23T96/Y3Vsn8l/B4ids/6/DON78PhCCZnLZhf8ajl55os5
SdtriySPRY4CPaao4TYRIHDKRfOnnMaIiRCyWsWs8LnZyuTzz8XnD0I2CvQ4
oONfRdY0pTw/mRaK/CpX2e91So5sFCgiW05lPwDZ4nO+xMNcAVtL0/2+vOTI
RoEyZD+CsvlSocBbs6LEFyv5j2KDKNCPQ7Y4Kb/w5bK24KXywvooykaAHlO5
WfkAZF9eXnJ8UYJpK5bziw9CNgr0ONC4/iqyq5VV5JfZQpbPT6erD0I2CvTj
kJ1o1oqfPL8s+Vxpan4QslGgx3QL/BBkK8Ul//w8KfMrc7n/pO0jkC2kih+B
7AvAzS0lnLF85aOQjQBFZPNUMfnLO5g1tfhcXpL4iTQtf9QOFgHKkP2ITWH5
MqnwzxNN4yfF8kdJgyjQj0B2eFYNDNHtpiGosVA2BvjGYE5idrOgEs9yhu4/
0eAI/AhTDdFEbNShYFgy81Z4cWboOuR5ZnrDUxWjmIS8591AN7dpEVXR8Ghy
zUx7DAcWHeYzp+49hz3A+4sqemvw/EJUdOZ/HxApBUJBYBGqB1y7zFENH+a9
zzbRLqmjozOyNtBvjG4yFvxEB6wSoMSUhvp8xePCxsVXdA/5ST9jPXk0lEnU
0HOEl6BoyKVo+ucT6HDDpFmE+VCxEWYj42R2WQCP4kN4wBwRjOEy1+zUDJ2+
8FmK66mig/7FsFOT5ldgvivDmuMJMD0QtgxV9cI36AdjouIhE6bHUvAEQXLw
eXj0soHOXkwciv2zBJqnNGtQ6Bo9DvOu1rjAWQGqKAsWHYmv0Iu2xPmlQ5Rm
ism7ugIGkue9ZEiK3LB2xnn3xOjxikqCUF8Wx2N6o9y0swJnO7rpbK426F+1
fNyJ/HdEwT9bP93MHfaHBPjUqB3X2w3OOwLmFqLqEgbWWZvIxGpAfzYe25g4
dCyEOS3pkZtNA6VnnsvQD6S/624OGrkpwHW46wFOoWStTceYWqI5UyReVcYW
MoUFSAF5MEaZeiFSXJPFbaF/8jSg89d+o3fdH47q1WH1K7vcj8eDm1hU1hOL
yZL8nG0yuwpEeVGZ4noJMwq7Vc75wcwsxBKvFlmwIp3difw7ZX4CM8iCW4Fs
irzJxUDzM7joK3bo9VGYWv8ghBI46IjhEFyKCXE20UXqPQ1xIT1WgmVBaG4H
spJUoO6CHZwSO3z8AaNmx4MyCxVlcwtMzSLRvl42Lj4xTjj+Gl6LNiClyszP
P0GnMCbdBbTQvy3aNoonWZGos5djEWiEknZrkUqiazOayWSC2Qh0xx/bKSfh
GaxMm9N1yGOANVfvn7VYgPMpNmJnJxteg6990tPBayJmOcCQ8agU+OLZ6wW+
mIX/RQNERE1m6Qv0tB/6YKdZDJ3DBzvY2AWsHDxf02TeHvOlTKFAc9Ee++f0
9PzX0HEBEsBEd/GYEqbFYreGQIS5qiehP3PiZMJSKqOoeCI6V/CPBw16Zob0
BkCuhce0tjvx6KUGy8FbkUxyEIsesX3t1weNRv0rx+LzmKSgzG5BZ+qasrhI
D1ltl8bje4fewRkPcj7dkujZBcBGAexxD2DKD3o8ZX883aAihaYTmWC8qX+0
F0Sh7N7yZGclMtFgkTgWvT/NzrdlIqo8G5iOIUXAVK7mBQ3ioqEZ21AeL/1j
PBpdx0Kt/77hB9//SDNdwBBnKPqu4dlgcPk3m/vK87jCaE8ws0T+zZIl0/3K
ffrifcTlUoVUhutcDYbVy8uUJu/Vdwz42LbV4E8aw+T94CmE9AbC8bF/JI4j
gRWwmSagHfy9X72Cv1MZ3UOKImIwa6YLgllRYTFTUgGJg0gIPL0Vp/7plDNj
XDADPYZJYE9e0JkCJiT03oq/1/kbXGhlstOmS2PJX9Lgia5omt6JOZKbOX89
ZeOoqUwxMCEbq0yElsSw0eDFqQ6KAzCHP3M8jdI48u/Z0GBYPCMSOZhj9pJj
dwy2DlipjNFE0/YiXrx7OsitID9oUKhBQ2D9y5ggLjZJglD4h/fmrZAcevIE
40vB6Ah7wS5BgU65AfLOf75FenpfE+ie3/MPt/9x3D/f1QS6Pznp+Td2uixA
5eQEYMG4ebohqD45A5Xj0Oi9kQfNkBqxjVj3tVqgs0HPHqxa75Zr33P/SukP
fOgCvH/dutA7QVXGcqnIDTdhYiuNk/CJKRDHG8XrX7l+F9417vxwHNA3GB43
rkE3YJoGhmGCZOBuGjHTDR1xaaoRhHH7dNcNdbl/1FH9yB95CDqNQuTqVOPk
Pg3rx28yEyaddWgQPuCzrYDFN6U4XRGH3jm18Zzbp4APM1Db/pXKE19X81Q+
oNNhdOKbIrLsiy102oNuetiLkOYbu+JGthbrXmK8/1PaG9WIqxdfQ919iwR6
ogSFwSBHeJzSYMbvVr+o+qfvQLOim69vurxJfF8jj/R/74nwNIY/UGpt8sbt
hfo9TTbdXw7D/X+DDYJGgMLyxZZ4zeMNkn5Pk5ARvrUN+cKe8+5TMVt3V9yD
BNmS62gzD70rL36UMSq1S92PTglgM6DM9LOZ7ReEjEWAHtHQMrooPTPQv84R
3asiymFY/Y5udCzowd/F0uGp+cb1Xd1OqzA2m4Ue/r6Xb7jh2twRL/u/7Aeq
Fu2JKb0Ht5/3bibv33MOfck8OSAUGjW0PqNId5iA0MNiaWdkVzFvIx9eD9K+
5PH0LsZ+3zbG8P7+4yXpN65FhVegkn4XCtUL/5vINrRp2vR2E9/jlg52VpzP
mQLr25JmGDYTOEACBd3vpAt6uLXmAQKa3b5M+8aFdmC/u7anWqaDXQzsGxHv
eW6PKWgJw0lf1JvchqwR+3zTomYR34fASDfwSfeNo6kJfRM55h+8YhMOPwhU
YO+CMJU1YdFyGSy+rTw0uKr3e3lQiPTAmIMp1/ZSDiO4aKwtNY3xzTav/A1z
sHVhqR/9ytXppXGs7BMJy62zkF2UkUNFw4BYwgLF2Q2U6uaOLYt4A6pVfVPy
jkXgoiRp0EA1SkASjuGBVxh0regKRWkTLEz8YGEadGx40bwAIVPiriWwRNB6
ZrwZRQExCD4W8jAuKfRxuBiF52b5gpV7NmZVfJ48mAI7XZyOX1aZh8fy/aPV
znVX+cV1Wc/y7sX0MY2uY5aLj/ZaZI5rj1oYSu3qEsUzZPOTccrvETuD3zQV
SCabLQlFMOvz6UjOl03OyZRls8whDiHskgW6UKQ1YBGmQrbENck4hE9wP2Vz
r3g3ior7cnIShLv9xrU7rTYmKWeXmI9PTv47QvYSwYZh3zX2hUxteoqDW/Dh
Fnfg0kS7ITAYarA3dOo74X/Z8FF0emJSBeJtctEmdtoRp+x2CgZ/0Es/Ap2C
IPUUjYKljfYR5x0YV2jqlO/Fd2ocxrWQEvipIaSyRehsB+mp8Z0IC5kdjGs7
mtD3XSPCa8IqDar9EpPR+F3XvrZhp01XVdMFelwllLZHcLfpbc9gqHf2O0fk
rX8ZeTMb022iYHAaQI4zynKrYGAqrtgt6Dv35naEwp64wRgGyPtrbIdl3xY7
2d31W+t3hp1a9dKDX4GV5TGYn/43UQ+5v9hDcmpld8i10yELX/Tplt/tNViS
O73txii+Y2pCGQ6TdUIjFH9kByw+8cf2oP3gHlhs4l/vIZAJu/kmwEr0dhPU
xTRjwdS8mKsZ37j8X+ltanxcT7GUYxGX7yBe8a90wmIzo710G/XObdfrp5jK
xfazpeX4gZubXt8rYsrvBZ/9QPBv6lJ+BOhP6OYd4vGNbvbM+U+NIhUqO2jF
4/WTAkb34BWL1k8KDU2K1k8KAk2K1k8K90xMrZ8T2JkUrZ8UwpkUrZ8UrJkU
rZ8UlpkYrZ8TgJkYrZ8TapkUrZ8UVJkUrZ8UPrkXrY2/M/A2RpMAhH1+YW+j
uOVmRN8nHggqfk4yLzZRZ9ke2F1LmglQ1NebKIw1t5yJjm2gruFltAtHB0Zi
Fult6q/3RJxjIcivp+zv9fZXGtjz9UyUG8z2/5o6OcGTljWH6QQjXl96UGTY
GIOXIqlTD+aAJougUOngvAcAmo1VVUHdNmT/TMr2k5iJrLo2BkeAKuVVnjpq
YPkoIupYH9bQ/2ZzX+iLzcTuLTU1MzRiilNyTK9rRy/KhVXnXfcaHYPv62E5
MIK5YZdsI1PKnMt4kITBk0Bz2p7dyN9OeHswwS13qTjo/Qa+2NwXXYCJbbPr
wX9+7K3jo5DPhfEl08iDy6hf/N7eDfPAxd8vS8WClWDSMJWQRzj0ND2BdWIH
jzDPDzteQIw+faHBD9H4MQyzUZnfyUsrBE/TLi7nYAXzEsFgnHTYI52mDYMI
Mz78jgWrCRk+W+YzGcELNEN2/VLt1j8ifi2XyWcCsJuOkXQ0vdQV5mugNBs2
Glv0cggJ04pmAdqi1DaQer1vhHZWWcaVQR2HuDzoz/9KWhf5TJkXhB9H6/I7
aV1/kI1lyE8rqylR0ug5hWwo6aCwQLFQLubzqVyxksnmMjQF008kVx5ZMxNm
TcwZV6AH/ks2koEjqsQNSYGVJPJ+vgVv81MMzDmFn/l/jliG/WzRZ4ZN5GYh
X8hUosOLK47oNWBXC+hVZe+6PSJ3BhvPvFkdDN9Cb4wfTrCOVfC3kSHOsdD0
PhyLQqWUTYIjNjj2Lz9EMBTlfrW7ATUWZUvUcK14f8O+v30ghwpeNCteyMn9
RHIJScklUBQrWyg2xTFI/zmR30Jx4n+4+Vs80wmZd2AID0MN9mK4L1IyCvkn
FmXGUcYkWmAZK9gV4wOJqmMvUm9SZySDkd0PY6PHbis27PrDYlexiZy8S4Fi
owaKjR8TJG0gBnFGmEZto3ednABCoHPSSx57nLWyVwrKT9WlsFBqjXZD06aw
PkhQCMnCMIcgJn8vojR+hV1XwqRkQULWUALfJcGkYw6MSWfl7SLppqnaijnV
qXJ+dOTdmdhJtoP6qLpBbRO+ZBqOrxcmvQb1aTuBLMv9TEezMTmOP7+V6GVf
CpeY9C2fNolp6B2DBVENTLl07CV1KW83wMflVIkLZ27ZzfESDzaS+aWwm/Wl
wn0qcLEQtrLBlCIM31iZLLgj8STEUJ7zmN9LLx66XYYXABSNsjPQn6n7p5Sd
JwrG/Iu2d0uGvkoxO4xeNnIwDVC4T8qAoaPUTjQm7+ioaoevAsReFqP4x+aC
hqXi4G00L1X7ho23ybWThdEioWxgwJJ8KGnmx+bJ/LxP5LKR7dp9bx35I57J
UrDuK89JcfreQ+ejo86EWxsuS9vNLuRMqAeAieXYdFdbF0NMGi3BYWFX1+bQ
wuVsg4nUJbs4Jc2INPcyye+mONzJcKiwWw/w2MstV/UO3NJdlq0SOG6HJYeJ
WIfW/gtFRETLIZyc+Ed8mPzL2pzlnZzgad7JyX7KMA78p04r+/mnBIQgNcM0
pGTx4w3+l992cv3G1x7eMHqSkKvTj1yxf4fhaMqUCjtWByXmVJfVQIExwmaH
Iw/8i945NBAgHFSUTWXiXYus2YYKyeMYTqMczbLXekj5w4ofFB2HYrEmU2N7
DDnY1v3AqLfCq/YM5F2xEh8wiOiu1vOvog3CCejto+r+3Si4uRbJV89cjrHy
8gTveZ1s7VaI6fsZlEqWN5IkV+Azzl5rYywXvS/f8N/fEwzFyv/QcCgk8sQh
gZt4B4VDeSdDaOB4PtEtlMeLeybReepyPPb0ZdHPlLknPfInw1KmqLrgXoHK
M6pQfCbPXL/0grDNrrMCLflM8fgIS17htXtWu+K+RfM/KpJiYhkb00DPiMwZ
eDnP27MwSS7bqcaw7yWRGH5qVJHq8Gw2t2UUBbxJ5Br68mAV7J1W1GGfo9cG
iYVEkSYpAEDduoZlwdIRUQQcs2bUqcwC34J7oThV9mSdotShBUCihLH9C6UT
l9VlYh6HvZmH8bJ4UG3cu+JsYdE57xI05hLwkur6BU9mfkkbNF3YeUF8ZRA6
kJBZA1PCcK/Sq2IMkAXTZ7CiM5715idHZYM+OZEVdnEWuNi/us8yuoKOcyDT
qU871t3Jye2BilLYieLYRJ2Ei7Xg/WFi6cEq2SpR9tbqpH3ixkc1+PCUK9Gq
O/TD/cWu4hED6ednZqZ3RW1MY1tvb2Vd/fR1ulp/PWbx8GBgRt+OibNEDUna
ZEhmaawx7207EH9+Rm+Mrf/0debYkg+RWuKb4HssTxa00nBAU2If5VJcdZMf
fAuaGAstlFccy/yJR0c9ttQx+ayXTCP+/ivC9MrCUTsoKMXWYxNCS7HV8D6Q
yrpp4RI83py2BMuS+xOzevunZvRyjJdOWsTbBMOBX/jV8q8ZIzOzHA2HHSEp
mn44jACMphEqby7ipA7YtA28SW0JxzhDMa1CJUM28zj0KH+BlG9lj3Fm3gcj
PH9RKLnjfXOSSzQnXRS9fVbSDbfGajhJ9r76Rl5ptug1rj31qmJTze9s4FuZ
iPntgiczopp2kPmeXVoRfPzwe7zQEeTz3hSX2dcuG27XYVmNY9Lse6n038oV
T9Pnb3JXbPIfh67x00O+ni+NYv/5tsn5zv0qnGZP86fF6MPcaeEUvTa93VGj
Q+Uzz8f3EOnM+9r/S/AnpsUVuM9xrEqlHLT4z//7f3rA/vP/+t+jf0Eo2Teg
zKXZFhT2tyiU3JtQvnIHoHh/iVytxJBWxvv0YtPWWiqlBMrv3mX/wnsXFpWe
QVJtmsLa818FCy2+IFKoDNKmrV93cf+hblytpB9WJyl9/EOhq8Y05ayc91dj
+mGVmMID/QHQIwPdX+/ph9V6Cg/tB0CPDC22otQPqyYVHuEPgB4Z4Vs1q35Y
varwIH8A9Mgg36yK9aPqIIUH+QOgRwb5rmpLP6yQUnikPwB6ZKTlVFiLgG79
epwf168PkQ3rB8IPDWzP8VFor/+V+r0D1xNMbpNtxDbdsQ+9pNs83t31HSOg
Qt6jr1ulumKML5Pqh6dBPqYv1D7mow6glSmGTi3Q6MJ8DHNibS4Fy4aUPtQ0
fXzKsqttaa4hdTdSZdd2p2AjOp7ZD0Y+GqKz9dhS/No4aHp9kqKLIFYJ9rMj
7n19/N5qK95B1z7Tn6VElOWYMtVvIRnW0bF+lr7eWPhjopOJEj2s/q+e1BRy
mFcrNnrCdHKyKXDrWRXoU8fZ3JnGMGPQL94all+Ey2uE3LN9WDleU39KyEfp
naezzIabYtuRfGVbXt8P4Imd2sbUhI44ICkRWXAu+jlpFkGZEeI9CPCZfASH
N9H1/E/Mc+dPEvwwLKIFcQpRzy116aXeKX4uqxcNJn4GiobJA3BIMHIsbydB
d/TL/STnvqgw4bwlvpsr8RHvNUofvxdFNEEohm+727lQBO8hjz6es4v6nPpW
GUf5N4zptG7uHr/tm0de7gMjO1vHCyzm+YQCD5142ph3dM3JWM3KMlz71DuY
AjSR/YNI5FMv8CUUnjJTpjOaCQUjBeRQlPP3ROtwn1jdp61I5D//PGZ540J1
hU5ONpWFQCRgbaGTE4zSwHMgWl0Ia+W1lIVXsQnxZKWaJS82JIic2kb1FM+i
YbOghc7kI89bTkIRHezWJqxIdLx7VeDjBHL3djA8cq0pC5bBI+J4sesV+nuL
CWm2mCz9LzvT9l9ucg5Hawux2vQYePXJy6XkB2SEagXhCQFmTfIinWKGhRJX
8Wqqs8SqdAnCHhsIBEux5x6yHU6ceuW7CHolaNJW10RpbId90OFicdWt3vxa
mX69RYzicmkFRgqb2lxBUIafURSzUdINLGjlZTr1fGLkxaXCnp7OTbGcpe6H
2XvZCgHZNT3XA46DpRn5holbFumPKyNc0z2ElV88/NRb1H7NbmAnr+i27Ut5
UWXBN0HlOTyM0mWWxJZ4iRRPg36COAmGDg0ewtzA0iax5pjOm6UAJYjMtHu/
tUZEPBsBocOgY0YZlnWBpsMJHIZe2iufwyKHIPAxPW2RvI3XT6SMcMY0ryzL
lIXviL8gfderf0wQZqzN9HrO2IACfqpbP11oihsEJ1LRk/XtZLZjPGpgOYhE
JsFo8k2WGNibUSpZQBSx6RMpZ26ysm7QoiOB1z5PB9RikVFk4qew9RJOU0f0
MOBLdk2H6eFDw1DR9Y8ZQ3eqsQZ6R7A4AgWEFmr94isgm41OIYQWNbUwzw4h
/j5HK+elK2XYagq5Y79+69a2uSmfyKqaRyt2+nEzodM5QJodO36ZKCuU+Sx7
NavB6f/wSwjGu5ffFUbCOqc5rnhFBoGFictDVhJmvxPTgMsxO8AzqM8cpg1z
BdOEYayOIVLaclj4I+CEQnECNKLLN1r38A2fuL8MEHaK0sfylB0SnDYuQ+c6
WPMWmREIhwyLdTZnXrZbVlgvOBulYCn74KoNJVbCbcnVvRPWTYLtf74Z8EiN
Z/h44yy6sDYywcsOv4stncFIgvrTQB6E6g7TSyS7ytQxptpnJ2WMpz0uCBaQ
FGwBKNTwa5OKVpb0fCt7cWR6cKIBgOZXspVmhiIRrzgwmlYqaCYhaRfI8T1j
xEk7ZcpJoI5EOXBJ8WSBl94GET+PsGqvQPH7HOjNfkaufzoO2b9GqfrF5IsO
6mxvcMHiQDYKa+qoucMbn4+O/le6WwfTgtq5kMqdRhZgACN0n62ugIQnfJuo
qgasiXzFeXcgJ5hCDbc9ouLmDs9VVTExxTHI4wWqikFWSraveBn1vYTbeGuO
0HzoiATata4esW+ZfxhjzReYIA1Ngy2RbG2nQ2JHLzSajg6RctceIqH0vmep
wR2PiWAL1BWm1jP67mnGDI9dKRYciXrnUubmhBtreytMkQyEIScbdG35DgxF
DbL0AT4Bi0ZLPQezRDsTWU5y2zsG3yTUp1TQ0UYCgvvRBdHXaKP4lXUBLY8V
UnjpTFJFRWMBwZoo+xokC2WlBsrUtYI80bD9bY7yj0Kn+rFRzBbx3DUYS+wX
pN1qGiq7wc7iyjv1ODiN6WI25W3QEYhmzkRbeQ3HIYXWMI2ZjRTtpbnzQduc
snNaKjxdJs+whjFOlB1BV0d82bg36kr00mafBh8dbV5Hw368WgpYmTlgaeaC
2EusFJ5P48e0lLoXphG6EINtG4Prfqc2oNedKW6/bt9xPQpOM+OzldOF6o0/
wN8/06QLKcgQy2iI8SQSi5LfE3nsIeNFGmPUoIfHW1nTY/HYaGHeqXcA3o9w
9tbLUTVSJP0d9PbjppiaWjWxkCOfTWW4SxALuk1YwARYgSJXQzEIym0Qq6KT
5eZKMNrv6zEw3kYvxeN5bAh4T5iSLnqJlDCX4pT4bgx/3z4QyY3KJ8YzR1Ud
ulMwp4WlIYV2buh459D7riAdHR28m4QBIZ9aYIKJ+jH3pRYZEh3wp+jlp+PN
FhgZP6VOSiZp74aY9zlPMwcTmfeqpcB2RvSFYhk6vRjKZ/gyn00fJ0MimwyJ
LE8jo3lRCXdXwyzoNjnGS9deV4IQOjukdwx1MIx1eEz3eS+e1k6X8tnKFoyL
C1Di1nZgpoTyfpqpJVFWip56eWG3KtI5oaWuXqyiMWmv1eHacq5sV7zZxkqc
EOBE0I0Hvu6xB1S/4TQGPX36QLSBZWRmz52n9Wq5BaqugLYCDHtvWLAHhlKV
xmJZLublZeehWeg8ZvIvJWWad8+W020sQZoSBe9j4LELKB3fCfJLE9QjHbbk
TfuJ94TeEJQVPMZIF4Qyfl3r9GtY5+JLNCWApFiSmlLdGJ7d34A+Tm81StxP
9rv7acEj7EYep6Z47ZLEDWHzEQMXXXDvApd9L7jscXD3hXlggbcddFXoVGmR
sA6Op/OwMlOoZKnKnHgV1JnNgB6IIIoYBL+MV19ErtdHOf3lew8I+ejF0u9q
fozqJQwGrQp1Y6bY7pheKfmF7QSStxPQUKR9YjT1C3NV7tlwUPTu3wXp/RdU
//pkqmBcY1T2UL8Ne8FWj3+lGScnnSmlM/l02J3MB+5kmwldPnAj8orNjy1j
TnTqVwHLg9dEEJYGnj8puKyyxWKmUKRr+1w0RW9xn6mgALRF5wqk6tCYr0NJ
SMf4ClQwKnAdfLcRj4JQqQgFCszfKlVRn7oYrQpQ2/QMQjfC4mcWPGOSNnxZ
ZinaPJa4QlWAdwx+TOgosHicN1DQX3WY4TWvODBUHY/YqAUGyufMkKE1mNo8
/EsFDcZa4imuLEXuj3kP7BTGxBJ2j2zqP02IUFqRhWKlXBBKxXzud+U3IZPJ
lErFYjaXLVMifwmniw62HyRzSHwSv/qWxVJFh1GIRsMHS5Za/nR7Q8a6Iiun
RXTUU1lK9xCHoa0Ar9F1R7AeCH1NR226qg0bqH9EMFHFJb9xNvCKzu/nusgJ
TOBAo7jUgd/X/jD79NJk+FwKXvrM7d2oRDw2l/qjw+MjhKDqPkNypoA+QfPw
wBQGWz6jxqDGNr/oErOlJT6k3Y0thUwOLiiLniTtHSJdSigc+QlyIbUgGNlo
zxmBuwEdwnG18OIxpnaKJt1BUxinN+XO06AteZ/yHV3CKQpJK7R3eDxZ4OeE
mDyO1StbBWNeH5gTm1EGxQCsPcqleAzI23Qylanu0Ja0KiF1XdBF23dBeaWa
WMCal+J4i3TeG1C3U5abRjGQLpTyhXwhZc7MqD5HhwtCJQrBf0q391iWUojl
wg821apLQFTsqHCKHjrqxCu8ukRSNvyZkvQ0sniaJT8p8SA2mZ0BrKxMbGnl
VCoF4CwhJbPEEDhrSKX8WHmNHp/iE08TpHufnXZ1EfYRVRV5mAsTZQBIV9mV
FJGXiXpgVraI3BkCmbfSmThA34Cuim2rRDbw6q2q8Lpoz+CPOV2gM2LP3bXL
u2vxdaFoeJy2iCyQLTrZ2qushYWe7aToM7b002I5a6iVSmabvnijKCycEEn2
jDakaDKqpvNpEHRCJpsNqBmCo0xIWEVUUvQBu42ZLru3k3Wm19VeGmwS3OlU
1GEP3+rXf8xwhiEcYh8UB4ZKeFNxpBlugmy7wGVA75TQHRB/SarhArmWBr8G
s8rGAwhvC0GH5ESJonM4H7eJ38AX6eBbeq4e8v3tlWUscgb7sE1DccLJZGxT
pU/YhrSivzAPRyVbqAjVTAE4+qzGFzJCgT+r5ur8mZDLl85yhXqxnKcQVXGx
4qKTR6cNn6dmrs/K6S2pysKHMDwFdjmQozwmYeDxTtbhHYCNwJi5W6ICnrBV
kxYy+UK5WKjk8iMhm81k8hmBKR099ODQ1cAsONAy11sI02cpxWLMdmgTiO78
IFIrk2I2K/DZoiTypWwlx1cIqfCFQqE0zkmZcXlS3lqOl0q3x931rjbdq4pm
LkymmfhrMqoQ+JuOVyaBoYLT7AkT2OHAKl1sbXr4iPKvnZ53ij3j6rW3og1g
UwDihqhIf6eoc1xUUiDMKA7+LAHtePTgR3dGxMFm2wZNoHFw3/aURXSH0t7R
egBrYK+FYOP1NdxY0r+/uMRa/xblZ9oedROwdRLaQrT9rwF8CkkCnCwVlOCw
qhh6SGckm8+USzvKfXinxtN2Hg+dNnme8L6fjhqyqIP6Bt9awTumJOrPINoD
1WzbK4AvaRogrJGxQ3U+qEl8HL7RHBK73hOq11EY3lFwBG3QLFE2IVTvzJfp
MjXRjdruEnsA1GDAAJmFTwE6wTPiQ9jscJN32dvF0pYAl2xZjyoyKXxE2zBr
f5TP5kpFoZJNY7aYqWGtR0IuUymC/rvp3YCt2aGTHSJL6KGfymsfvzLGZpLJ
Y14aY0ExHbrWXLFngKlfJRJ0ECW0g0Qe025m4hizgmGWCAWER3QVHcBBkUAK
voprZcLPRVVZGxabG3E+DmvZ9Cez3kIal6KHNh3YlYAHafnLYIbBcp0ZEre7
5bIXgZdrCZoB0W1Q7yawB1JwoDOjxUV0kBQECAPDQAlAT3vpb9hwpxbAEWnN
XOaEmxKwA9LFSrEi5EsFtgA6XfTngCkUTg2iec/YZucJO6LDspOCZCC0+DcY
eswzHGiQ/Y2wCnlQMd6GHvkE0TKbzzYxl5Gr5afME7E5N/KPghyDnatgXhPQ
jEQ83RHnUQLiBgZd6oHqYKc19q0pzkeHlGgMwdqxqfGkdIGypJQvVfJCoZAr
lXNFYP1MMc+/8NU8m8u+IVvK1ODOLCCS8SY2ljWmH45AuWIyyw+5YKKcegWQ
aXSDR/LAzkzvnFIsCuUsbKu5YrEI6BSy/EOmWmBYnGEsRc8Cm287c94eHMbw
MWxl9GM+ny8IeSE7MhjTYv4chypIh3SuDTb5SkkoZyt5sH3z+Qy/nCg53zY1
LBvdSAMg6oTEIAQak02/SbPQ5YDqaVC60x6PMUNj/TebOxt0jo42P5tEpmx2
jfEr7Eb8XsP70xkeB9ii5nCT//h3ixugYm3NCIb66XghOtzMZucVc5bhdIv7
uJpogdHBtRXVwULOQJQ1Pe2wOVDt5sTG2Dl2pgO4nkIrVf5ncwJ9ZoGDtVo0
Rti7Ge/l9QqqjbHQNtnzMIfEnBfBh/+JVCvGo0t61IjHmjAtoXXuR4j5xcmO
WPE1Wn2LOFLqlJ3yYLQZTTwW5LcZr7lazesQ8KZBkvQsZX/aVxZFETlDVmz/
fJd4xQ43l/UwQVeNHgwx3wULW0LQLBQzeHzwvAs5hebKMQloGszJgaflNANx
gmM/GnSb7vSHzUCERnITeAdnwVdeNHSIR72sbPSW4Xi9laDXz2YQJCvwPmTn
qoi0/waVsBTLj+Af1oXxoN3uh+2de4Vw8IJKPdCKxWG5ynCQFUNAZHkAPNGD
RNsTF7DviDKCpn9rnp1+s9NlZCBacvvTyQmtKo+q2MlJ9HsMOvBikWNONo9Z
VqPAhxdb8w0Dy9NnpaZQfx5Zz3a5k7mY5tY1M9cXzcwDaaRDzsC/Bug4IVJi
464i3zYNp3rz2tbleTb3ciYtz4Y50U6GVBygpEjl2otMQ7AnD/Zifeaoxer0
sfzMD9ptZZkMqThASZEqXJ4XlYq9MDR9Zq577fseee6WJl3t4SYZUnGAkiJ1
N3p8ad0+5iaNpdhcLteTaqVuz8w2cTLJkIoDlBSp8+ZIWmrtdmNsnY/uC3fF
dYM49/e6ouSTIRUHKClSvVHtcbiWppmLVkkaX4hus8rP76YP2WcjGVJxgJIi
9XT+fP5gPi6fCnrtTnsd3eebF8UHpdl4TEipOEBJkcrbRu5y1b6+fmgPhKW+
mLkGub+fklp7ngypOEBJkbopnmtSobzISIJav8u5z53HTPVhZExa1WRIxQFK
ipSe75LCTa+2WM5WUuNcl+9Jbw02qWQk5Kk4QEmRGpP+69XVYtlVJvP+5Lw3
WRGpZbTNYT2hRI8DlAApaQK/bguPbbkiqI/Pyktt6FTOntZ39asmuTW770bq
TUCJ975mzcifdfv1we1aX1xVqjfnotN71h/EacK9LwZQUqSW49GjXek+yRW3
YnSzZ3O+7CxKk8VDKyFScYCSImUsyhO+JD1dXBT6T3xXe5aKndnd4IxvJhQJ
cYCSIpV1b12xLtTX0+erejffGo5463G8HCrnCZGKA5QUKfMsVxHHV8KN1c6P
qsPuqFEqL1a9obtKiFQcoMR73+qituq2CT+oKv2KO7u+VlXrIq/dVhNuM3GA
kiI1FFaueXu2fHlsnA3ateHDdNB+eHLkl9dyMqTiACVFatZf5ovN5VS7k5XK
5OVJy06eL8aqPuok3GbiACVF6rZVWjdGc1XrD1ZX62z7oTh5dZuGXn9+v/B8
E1Di1TczSUeVSXPSKBqVl+Jl5W7uZDLV2kVCSsUBSorUVMoqz5nF2CCzwYhf
CBl+cGWrK/GpllAdjgOUWHhe57Xq5KXQPn8ynXr9yhrocum1Lj8ICRk9DlBS
pB7cc2m0bpz3at2O+ygtstfd0kPdmPZrt8mQigOUWJ+6a6v6uNlpzHipd0O6
bv3u+mVVeFzcJzSx4gAlRWp1d5urlV5ur/WppJils/zTdaF7fjusPCTckOMA
JUVKmNak3pIvXRlmvf/6evZazcnNztTI9RMqeXGAkiLllEVj/HqWK+XVe+Xy
1bqzrvuPpXnrcZ1w+uIAJUVKy92uz4oPlzevK9GVyHNjZJR7el5wB51kSMUB
SiynXtov0nh8sRBHRqvBPzfqT242n5tO+IQbchygxCZWvXxzJtzfXfKOcWUs
WjfZ4bxY1zTSSLjNxAFKitTi4SprKpOnQutBqgmry+VgclnTb6XmbUKnWRyg
pEh1W80HRR+XCw8D8XL+8nzWmGlnT7VST0rIU3GAkiL1bFfuOvneWXn9qM2m
2eux+HQmiNns5DIhT8UBSopUpv963X99GN3J6mPh9mbUve9qqydVt54Tyqk4
QEmRus9128IZGGtjTbi/7a1aN8pM7EjC6zChjh4HKLE+NRJba1Vrto1L7eWq
dHYmPd4Zbd66SmzNxABKilRp8Dhwz8q5C82qvNTGwp3QrOT1yn0ul1BLiAOU
mKcG95Np9vGqUb12zm9KT/ZEWKn5a756ndDrEgco8YasTa6W/HhZvrDl87Ga
t8XLSqX5mleIlHBDjgGU2Du8Viat8muvIC4NazwaCFf9SrNx23i4T+odjgGU
FKna43LRLRVei9awI2eruaenxdO51l5dKwn1qThACZByJxr8zFZWzaeHQi1v
DFpz86m6eBiOSo+X99m798/f25CS0soV2qvH+4p0PrkzlVxtUnnJFMlsaT62
Eu5+cYCSIjVojaqZjFAU+Yuu/lCdt5zu7cqYP2nPCVk9DlDiI6Nlib++z9aq
d1aGvzl7rZRItbs6G+ndhFtyHKDEhru+HkviZHGTrfOd2e1keJfNlu9vmlez
hDZyHKCkSFna3RVpjp/FVbao5gS9YCpOu7O6vpkn3GjiACVFqj6dncut3Noe
95oX3RtSll5feUfqdF8SSqo4QIkp9XQpSoqcXeoNRzxfDsZKpzNxcsNMMyFP
xQFKitRo3ji7rl/Zw/vnqSiPCytdfS4X5cVMSqhRxQFKitRLL/dQy3RFq9ms
5gbd8Zl5f3/urKq1q4SMHgcoKVLz+fPNTMmvF+cjpbp8tHpLQbKaM17jE/JU
HKDE9szZXL5wLl6HTr5ZEe5Ma3LR0eWpNswmVF7iACVFqu26o2rTFYSzoSWv
LnKd8kxbZp+fzXJCwz0OUHK3ma4Yq/nZaHTz1FnMmnpBF++Lz52H14R6Qhyg
pEgp93atVlXLj0+8eT2slmzl6rZlT1SlnZBScYCSIsW3W73bfqG2cO/upevq
NFeSBqulUR1qCRk9DlBSpC71y8dGady6udZqq7uHl6LtKNfOxVISEsqpOECJ
eWo07pzPruWz/LMwzejS66r3tGw+ODUjqSs2BlDiM4d1/uXu5vym1S9n+bE9
vxndtjpFhajCY8IzhxhAifWp85w9emzqk0rnplwaLrKS8JKf5Iqri4SMHgco
cWDJ/UX38VF4bAmNrDIYtdc3eauuXdv1VsK4oDhAibWEC0GvD8iyOr67HC3J
tVkpz/XHJ2laTMjocYASuzie3dfMpPNcdp4fDelWU56eHqTBctlsJ6RUHKDE
hsOjcpe/eLqyshmLFG/mLW19P8iZPYck1BLiACUOwXmcrjRBGTtFMy9fllZN
4fFKVjMPAzOhNRMHKClSxcuL6bWZzT72V63h45hX+LOV0m29du8T+vLiACUW
CUZbuug5D5eTs9vH2pNxJej6dZEITT4ho8cBShzDMViP2xVlpl89X5UGz/Js
9jh6cFazrpNw+uIAJUVKHrXKVumy23qu5gtnPbJ6WtoTTas65wklehygxL4E
/lUsF0eP5xnbXJ49nC2HdzevS+W6ZiX05cUBShyZkO905UVtVVYHjQurppx3
nsfmWa1v5RMqeXGAEutT1evKunluTNQ7YVlfLqVZviBrL3NtnVBHjwOUWEfP
XL60J2eifaOpxcojX3lSR/rzxG6UE66+OECJRcLsuqU+rqXRWne0xTADm8RK
ldWluEp4ZBQHKLGWMF5eViRZLU6UXmZx1ppWB7e3dU3srRMqeXGAEke7OGTZ
HndbF2c31xf1rP1iTYeWbtau5wl9CXGAEvun7M5z0SgtJ/nZw8itXRaEYW24
4JfNVUKREAcosUQvSuV6sXdW75PMKl+vvjx0c06+0ZPySSV6DKDEYV3WWSFX
Op852Xnj8q42sIb9uQMSppQ0UDcOUFKk+j394nFyW6uPuv1lbqZXM5nXabGc
X7cSrr44QIljOLrtUca+vLwtdMncaOiv9xfneudcEwcJ3YtxgJIi1TqvVXOC
Nq2SmTpt9vruaN2uChn1opdw9cUBSopUZcJnhfPuRdEWerJkjItaz8gUraul
ltDEigOUFKnyy8uo1RzmKkKnMW49Pd3cOo/d66uHym1CX0IcoMQhOK9u9lat
qY/deas8vRpc19RV63y61K8TTl8cIESqwdIufE4WDTBZ3Zt9Rx2+9BrqQ3nx
kF+UXeWqWBgmlKJxgBIrVvPbzPP9aNWuNoWy9aQ5T+fZatYcLdsJ1YU4QIlD
FJ40+fHiRp3MiDWeGctOQ3vqL7PtppBQtMcBSqztZZ6Lt6ZdH9XI+KXX617N
6+e15/XgpZGQueIAJUDKEh07bdt166nfvM/bxdpAfCTVSkdrZ3q9G+H9y/BN
QEmRuu6ddUb3Mt83hq+v8qxQz5w/GffqVavzfsXqTUBJkdInlmwJw0pPNov1
0fw523ByD09zfnb9flvrTUBJkZp2uwunJ3Qe7IfmZJx5KOjdWX8oXl4a798E
3wSUFKm12Grl7btJ3qxNzjPtq16vv8g9TDNSK+H0xQFKilRdrArP9ZurJj+W
rwsrXp7fjQevaluqv1+xehNQUqRMZ95+uq2/DoxHvV7sF15VvdiWGoK0SIhU
HCDvSnsXk5zfuJjAw9Dto6MOzRdvOafcBADTwivci/+aXbel94stUbHZfejt
suXQgOassxy8v4opxzH3Mb2ueo+plPfXmfJKTH1i6VW4f42t/OWVJrGT1Z7y
Wv1+hGWO8DY1pvxXdJemqg8XGrD9a+c0zzbmuqIlIzBLNlaYqg2qPDnrNf/8
E350O8N+g68FkML52TGLPpYcULBeTqiI73Z9sZMTOuqTkwOjeHaB/BOFyL9z
twEeNIUk5m5wFG23VMx4k/wXLz4btDZZ6BsLExlyikbzCDsEs1tMsDYoDEQn
rJpIA76ldW3orfgh9PKZVrP9ElQGimYQiPAg8E5akb2KT15yTNikeDa9C5un
k5bJ00QtmPOYJqIp8tnjlM8n3kV5v4ga5tCnwwD+UaY6rWFkM/pZe6ov+eWX
tusvfaJZPgA2FtTSpbVPLS/jFZGPf6cV0mSvntfJCUvMxe7Ks/42/dN02pgl
gE4C5lR3NXrtn1VD2IaNlUQwBfkPJWI+lU3lKRnbwHtBHRXMj08n3bubTxch
4Ayk0Yka1LFT9IWhLvxSdkDrcJ35k5PfKfb/+AdWFuhXWfEr7AbTHHEiR2lF
y/dEyvhwU8KyTGM2JSAV1jLrdTp1dt++1u70RvDjdy/JhqvImFSPG5KVg1Ij
qMmMpZ2QnjHjSHFNEIv4AF7LBmcbQQIART+KpmzfLWRxCs8at3d19lAo5stl
9hBLOsEix0SP1Q4bNa0Fo8CSoVix9Ae0Og72HBqnnwbIyzmBTfz0CUd+nflY
rLltrCkyDXlKVOiNH6wBgmbvQ0qCbmmFM6AOwQTrm1JAyegUGX52D0lyrPsz
WhHU69ygFbu4CAPZ7xjp0Va/flYrHpNlqHao9+DN1Nj3lBiL/Y+1fY8tRzrw
mJfFQ28cycWRY8KMUNoh2PQcTHOK07zJo3FEs0OE0g55TGPCvoTJ4WmuYppi
xdL87Bc7iSj2Z554q0oJ18VsI0ooI80SS5wEaZMNVmgJU2KYFqYsxPRYaVNk
9dcsPwcSzUwS5LKpeRUkRE9zqAJEv5iOXwWJykda9AGxxn3O3/sP73yfxLnI
cs4fbyWdP1tzukGraNmhmlMgdHQZs2VskmxEK2aNNzVJ4J1KU+QwocHqToGc
Y3lifEBBtg+chriSRLahuqx8BQd6E9OCXFDKsLCHgYVIZoaXiF81MIUvyzO7
lU3EyxCCWgbms6ZF6ywSqWCIaOJIQVvSfSAw0E3tQK9YFJbVYLoOEW0sAzIm
XJADZryO1o8MMv6nQMKCRgfSlgCVFpEcWTTdDBbsgcmKHwR8Az1EKxUgK6Ow
wwxMXpESYCnE1E+74pcIOt1UzKA5evyesUAr1mzDfDk6HR7qPvit7Y4ddW+Z
CK4Bky/RNDxRDoV9/ZOSIqlTL/W2SXMD0UUlAvP6WVfYFhhiI3/NnsITL2kL
LXSH46FpqljGm66XDByUNNiquQFNBn4KGraliBosQRBf4kQ85YauoYEWUnUt
+HGn4Nq3VXHB1d0xWc+NU+4ckwViM8KdixJo36CNDwx9Oja4M/eUq82IPl0B
cm1XRF2jLRpLTHFl4I8LcS1yDUtSgGewb9vGykSKqGNiMGU6Q/HPiN3BAjwD
aWYZ0vyY8iDx6BaWUaLChNGb1SJMeMuyH9G6EbQST8B0ngbkFy75TinmF10N
qvBh8SjFZnx5qMiFlwPI9KrExRSWDBK/eaIw3Ir1gjIDyIC7vMeFnk1Be/fr
K+3UEvHzGlE7yv8WUcMRWqKpyF4FwRTlUW+MNIm9TKvvBAs8tGI2aZz8ypOR
ArVDEJSKDpP3GlDfLxQLsl+mlZpoR3RR+inugl73bj4+HJqTaYMqQoC93cLC
vjIVpxbBGiuiIzL2CB7ZVFfZTCRr6XWJX80JreCzKdeEo3Q1zJ3vP6ZpzaB3
WoLE1wwxXT6mwtwUlr7bzwnVTWalu42AreM+YR8NDc/isAPTNVSoNFSZFaeT
1nUB1qTq1IacSAYqDbzUnHFsGUrzFJL2dNParmS8r87t6TvLB5/GljsGGW2j
bawsmB2IKpuX8UsjhCZ480vB6dRosjCxWsAxyIVgJuEcOkABFUQph6mN8aEP
h86h/Yb0rNVqXLgE6aDTYmLKV6BSXM+v68B2vE9YsoysZiKax1ihXKHzdkzr
yVqsdiartrp54NVdptRnFpb/jf8TvqA5uiiX0u0VTRm6B8+3Z+3t4sCUPn41
4Y1oYYpJSKhOXIuqIN4S21JmGIaYjNPTNlHd9IcUVA0KDfvPo6NvdFd30m1U
LL6BZaC7BP6swwx+so+5b5vF8w2+5WH7PvhfeM+sDO7MwBreQMBAC+zWuD8w
lbHurmB+XA23/3DGOpRJoQTHppTCOn2gXdI/0tlMGnHpWeLUhYVVe8UaASI8
KXDXEmx72Bx+ffFrRcWDCtdwtNPZQrmAVextFX1FpxyO16CjOTOa/7xYF/OZ
/Vh/aVXzrTYn5LEInUp0LHfWZUs06kSYivnpjHoRWB/YgjdZC4r4AJqIJmqZ
37hsGSbTdPhsBPU9vfcaQ752fcVyBGY/c0IR8WCpWbmGn5rVq2WGWx0S1Ctx
G8r9O+VN4qSmCqaVRfGgw3JRHVefphEgfyDXKwXIKgjozAf4jbv8j38fg1l7
6qflpIPhsxU6nq2RsCGE0xxuULJBBNmpqWFMvXyzspIC5QZ2LlFIKU6a2Ial
SDZNhIn99sGOO+U6gDZ2KeR5oRzt8gvrMzopvlKFeSRpEuNQCsZ0XsjnhWK2
UBptZfvDZH+j6N4+aocrWOLLkaKPPFeCPBpeDo7ZaGnd9H51OMByMfCx5gv0
UMLtfaXava/SCmvFukZ/Mp/Jpf0E0fgbiXGnWI4LMh4J8QYVkneGDhRQnlU7
zWDx+76iGadF3pOkfhpq+hIEIlM5eNRD+J1q5PzWxsxnMrDyvlCm3+C9BvvV
TY1Jel0YDfoZvv7azvzu/JYtFBihscyMCHuCjjKl37kecgNXg31tm83oQ9iB
DYc3WEbugKVaIHYM2PxPuaZFfV/fOEZNgqJpQ1LHMLFC8Vo3TFABN7BhLwUW
VnQgVmpipbOmaUyt7GQ4uHDtvjHN9R/GvZvf0aT6lYLY5Cf31UnU8yL5qMVw
mncizwzJY6sPG2GW3zvGXaF5CC7LQW5iznnLPlCLCefzO5ZjrlIu5zLFkb/P
jaoenUbGJLLWRkCnzYNGvX1dO46IzTqqwcF2eY/1OgdYHFvjPtUH94PjQ6Ib
D01GNv0yzUqp+Bl50S3Cqsy2VGMMa6+qooHn5R1uAZ01EFd0m26D1g1S+hPd
OQ52FV3H2TxoydO/JMxyhWKlUCowSTXwJdWWSo5Sq0mdFqNWpzmqE3Srj2AI
Ufoy73e8jrtn0bp2Jrsk49SrYWgpF0sYSGnqikzfVvVcWZCJIvJi90p7brVn
3ZeVIUlCW1o3S3P7UhUJuSCT1XV+PKhltXbvddm76T22SFbWn/qp14lKHmua
5sC+YYyuPHEbSQBc7XA9Zr8M0A/o7dIoH6hQFsKrJuL298Wh4C2bO4XoungK
MwKsQFWMrMCdu1iQ1Z8fNHveeyoIYJFsYLoQO23IU3m00mbPNw9KfyRePsov
zt2ifk6a+e9dNplKIZ8VKqOeZwSP+q1RmDCjIDMym+gprSM7qnYYDQeN6vDH
ECnRXoRwd7YeeMi4z6+gsCkzi7ITFHd4l8mkTHkSt4c0x4X260zQTKEBe0he
KFfCuzV0QrcTLIkNfzHNNdcGMzREB2WubBAmegTnmb8R0b8hjAPUyYSpg+TZ
bGEwKixIl7THX7fKzUgL2+ZLBV7ZVWeQOojbXxnU9noL2OrHLbsdmn33urur
nF08nY/qrflTT1b15zPxlqxVdzZ+ufkvWndtw+k3ax9CJ6GyTaePWXozw7Em
kqfrCYWDpeFAa/FSxEdqj8Urds16+76vPK8ubAMWZS5bLuxblJQL3yBMwK12
mmIdMO97qfWzV+IHzY7fO50geV9nW7UD35iRVv9lbdU7jWljCTMi5PIZNiOd
Rq/1T82nCjGnHpdm9hI9GR2m5ZeRK1QWD69z3C7ymbzHmahI2jPDjBIgXKfF
1kVp5vAyiA6s6QTmNnDU1AId2SugBqa3Al8cqn4jFAq4DoDYdQaCG0gK9Y5c
YeWcLd3/7d4JWwQ+MBCpRZgCnYSmYGtb+DEDouS7dh14ujUGgz7kZRlhb+Fa
COO6g2qkJV24cwcriWC1MO84G4vxxNWOArkcFWoiE9K8CFovO+NPe8gf2Pr2
2mTM2YS1TtzVhFYvpQcNyMuH6qpQMNDXJ694OjvGOYdpAEsDPWXUhSTqzJLD
gp2n3O2gilTK8WA9RAmFMSrbxUbe2M2EcgFMiPJogN51MOOUV/pm2/TaT43g
OKcWnFHtOMnCI5eCFp4tBAxfwwpH3JVI3cobAjcD+kWHI+nSBIt0Re2oXIar
mpaixoiYd9EiX8lXsqM+8hIOH3kJTactR9GoGmsO7ZpBOWf2NLP7Cn/2dH7J
t16e9WXrdVZS9LHquBcd1bx7fumq92bxvi93h0/F4lPZ5MuPz6JIrifj2UOq
ZrSLj2fuXLxwxcx07uAZIgvMUTTERDO5TOZztvQ5k6ETBUYe12N7Gp7eL/Eo
F4nNvJqUVH742R7Zsu3TFPF7XDD4PR+4GbroSwWj95Sribooi9ynBZsQfCmU
IjPyfROSFXLFopAZDVm5+ZEf9zFqbKrNj4b9xujaJPpo4IKRGCfgL6yKsTKF
iayjT0nIlHP4NdZ9tJxDFPCjK0C/3KEC7+1QPAPhi4wrWJ+DtQaLUcHjNB1V
Pm6IriDbPxb0pbsxCdUrgs8GBqy0LUePYfMLg+JCa8umQTuDZ1sLQChuk3uP
a+cAJDqhzIWzT0sJNWOyMT1RsEoqK72ap39m8kJxxPD/l2zmX7Jl4V+ylQPm
2XvQ2OMFFz5zQuGjveCFZF7wC9FSbcudkbAfXCjyH8LsKH0KmSz104AVccgJ
hhT9PjmfLeXKb0GnLrbtvQAkIDDtCPVAb2Zaw26TufY/c1VdRx70DUAv3uC+
xf3C+oI3tGwn8r7P7L9scJ862oT6+1M2WxQ27hiUPTyV43esM/4bYecQ7is/
wDgC+K+7IK4V9nHmeSB+V7T+6i5QyJWEQrJdgJnJzX5YYS68qTAX2AnRjOiv
8C9Gm2CZsYgYrbwxoDc058I+zRksuonll172VaZ43bgzuZiOr0v5SycPorOY
KeT3epHeN+RPtOc3h176IUOnfqVdl3z88GcPJdAQG/OrEppIxVLRGz16PrQd
z8eHTPxf5+RMLl/K50q5w54K3ydxWb1o/Gz8v2/2VFTlvXLAe49T6OnJG7N5
/jq5NMf6TM1U0QUhCKUDrpkPIUThhxAi4qPxCBIEEW1CP9mvw5ZQPKGunWuj
dGVMFRvZPlcQfIvYp8/3+WoKW76aWPLl+R0Kfp/fphDy23y0tfgd3p1D87rl
3UmEafxsFrPVQvmlLVS6HTxSzZYyvlW3Gw4U2p83hdDhOz666YU10AzXJOMY
Pg8B2n986IH3tWobzxzH6OzVQ6TyAz9p3CcL+2Q7tbdRt8AQoBppVmDnA3/f
IQgyKCXKmIUgLEVHmv2++E2RX5bjzKypzuz/hvFNv/Uutcn89lzKVdzu7Mm+
amnmin+p827NuFl3p2rH/G9oRhQF+8dFAQgxUQCVNyievK/3BAEIntChnLnR
Ht46jJne9h+Lgnyn9KiXEbamYy7OxRJS4A1bJtrmKNrGAH5XJWk6tgOuFRAs
MlmAQNTwBPdL83pQb3S3TKttwEjdMzA1baLap9wZUadowH3jcgJ3Luq8sEXu
XQvrIKbMjm61W82zbrBXOUDmfYJjG4oXw0RJTS+I2fsgMSjpbBH2/CwzyrIZ
YVTMuBWS0Q/MDv2Z2u7QlYtZobCnk5S4EFJLMtY+UnBkS0jd/3LBwZQkUIoo
6YRs6YD0CBi6l8k7l+fSYDXp/v5+cZHP5T9U6ub+KYjnEU3IvUU0aWDVnq7W
Rmk0TUA06qr5SKoVuTqRKNUKb1FtC1A6MZ3O2Bk21cLZGTZSqyBkheJb1FqO
utZzl7TXvXICahUqH0qs7Ptp9cEcRr16wX1pj2qZ7FtUE4pi64k3nhQ5CY9l
K1mqD/3jM+cojkp++yUc8e6HV5NN5HskljxBtPkvfx6xsOKqFwUdBBUHUdLw
Bbs1DWvbFa31JuQ9iAVnF8y82wP/FMHt9KIQu4CI0fz+VUN6d3rrHotheZeO
WIC4wW64cyLe3dTxzhjw6iwceblDZ1o72jTxLjXe6TMtvFkduQaCndCrR+KE
BNdgFAtvl1v2ZzoDv3L76j2zV78ybe6AWXN8xHE894V6P+5Da+o9eWly5GbV
fL5pnl9KRCRFNT+6mj7oml1/9MFSDfL9YGn6geJ0/LLKPDyW7x+tdq67yi+u
y3qWdy+mAVisiP5+qKhTlNX1S3tWWZdGl4viWFAeZubty6NlZroZHyh1Hbwf
Ktrv6aGxcNTScrp4XZ7fD7Od7NNSnxmda/3xJqBstfp+soriNP189nQ3Lz2u
B0tTbL6s5epkdZ/Lza+eesH4e6issctqkZtzKCPe25fpw+Ajt+/ScrFw3xNr
mfvxU3+5Gp5Jqj6cT0oDjdbWwu5pHEiWmo7s9sQXZ2YRURbe27W4AZB2x68l
96Fm8/zjqzu4Xz9cXdna/WTkDG4wZBEWhwc9+z3QV+3Zc7WSn7wSuXh91Vn0
/v/qru6nbSuKv/NXWN1LiwrkAwhM6kNCgIQQPkJayl7QTXxje3Hs1B8JmVSp
Q5vaVevaSt00tayTJm1rJ7o+bKsqwdSH/CkjgT7tX9g559qJ04SpQUjTeCF2
7ON7z/e5vueXnFLP58c2c5W4z8vkRnZuKMbJFbs4sT4XYXK6uFXe0fK6oc0X
izFFKc9MJ+IdIQ1YUPh3wt2lhLW0tRRZ3V6/UVy5GjeyaWP7mhqJpCub2aJP
Pbg36Pz3E3U9R67Pc1g9nuPqQja3+OHQKiB+deSjzUzIzWZnI6tyXV8rKNcT
tfV4NVnlU2cVvkc3p+ZiZjhlbe6UFpMlJbeUzU1P5RLl5Lw3bFrgHnbQ9Fu+
K4WdVLo+m9reqW5sFZTS6rYR06+lF/imfcYxv8dPBAtNTa/k3tuVQKI2sT2z
PB/NueGd6+FpVVlcqluNbD5Xz5ksHhAxJDWnveP2KlB6Sy1MvzcFGyR3NCV7
/FQ6ykQgEE/QtvKJcDgWCcXC0ehp/BuKZgVreoVPRKE+oUHn43NnGijUA90B
zkYj4dmzDzBAKxIKTc/MTIW6ElidW+u1MezYFgR4wNTgss5rJ5iQN8/AjMxi
dYzp+ji9jLTFg+GmMf+mntnEwtNYRntUIkNTodW77e47JEw4xORmQ1NB0tFz
Iz05E53BhVuSgUd98tyoT0Ump6NTIJV0SYIMnDo3A23+2HFaYxDy0O7wLQmF
PkJ7gZTWAxYQuaxosvU6S0RjKeVql6Wq6EXUOWID0RPGvfxtHpPUgHkldM5l
RIBCDyy87JA+cD0jV0OxtcmrPO/aanwufGOWJxJONeRB4HWW+P5vvTY4+KAt
DKEBvm+ASBglOlDKEvpJ4KV+o1Jl3aYYOkTe4jtcAqrxtgvMIq9D+EdAOmjN
tI+o05M30nPk11OihxP75uscnQSnRb33rkDfXTNH5R2igB10+yVqyjbAoWtc
MqDeSXLXsYuqZFctXqSXGeXmK8Pg4grcLCcp3DI4dlVL82NZoAF2IuGWt3ns
bXYd7F7FNAO776FQUVkBvstqjqJrXMauHRkIpVUkWeCahOgvzT1KQp1PXDCt
tIooSQmuwWgVW1K5XoJLvVHAcFs/7baf7rV3n7Xu/3J0+Pjk5e9Hr1+0v7n9
9+GXb7972nr9ur3/w8mbr+CCt7cen7y5ffzoj9aLB293fz06eHXy6aPj3w6O
9/dbT54c/Xnv6M+9k1uf/3Vrt33n4dHBfnvvi/adB62H37buvzw6+LF1737r
7vPjNwcnLx8CtePHn7Xvfn387A1cj/JOx1fifXgR+R4oE5XZCD9CV4p2fUSb
GMEO2QIYGlKJF/0mcVoShSLaoN5SLl+5UALT4lBn914jgJOwFdrgCCvALITt
QGyNRi/2Qdqhs5oPehYssUti2xViBICrwcGQY0XQApfW6dFplVydABYqBFng
4cv0oXCIotgSCAuyAHCqopypcvUhVcZ93nj4KoTQZYtmf39VApvAbYHOJV4I
YwHtr9tKUPdhP3gAM0Wy0YS8nRqgrsgc7IEKtkJTYzbUyaOjA53s6CjiNw36
5uZNgiuoa7bq9eZbVNKDjXgt3lSz86ImMiLPxLuIEF7lrvmLBARntwF22ZAy
qDBMWtUMBueSFrPLpvevphXhVJZZZYgROVduIEYSt8AWQDwLiGYGJ9a4Ii0h
mgt8zvECLzNVWgUeyqZVglN5s6CB5q25um7jzActD9DEB33hzVuBEXpIUKyj
fnzAFDUwAEV1UFe62iNWNsB0q3jeR2YxjVOfScyZt7QigiKBNunImCVXNWHO
lt18bvQx5R2MFGST5SJkic4McFwOMtsBxZIyFq9wC9nyMUM3lQIxivshGkl5
1azYJpLfcg2c05LGBI9ZjevSilY2DRPUH87MQfRugE/TxfVxwzQaFUQCDPYI
++A5lveMogkXauDbHE262HOhrfIq5BYyhqIkM0ADshDYwYA8HciZhlJ2GQ6Y
RM4RR2GZubKYWRXBFVKmXiEtiIO7t5i06Op44ADT1yxWZrZKM4HDjUaNYDCQ
rUDTU5Gsy1Xcn4sTXjJVA+7ibvN7GLjj2OLqBMRO0NUU03EYm5wwdTbA0Rdw
HD7EDGK6dTFlpP4/5F8PCE1HPsuuSdyULV5HFugkrIwLUZ81pLhagXwp0zxs
/tw8LMMXQQwaGkFV1XAnolrRuEKsrDVkabXMNNID4CtSx3yNgSlumqYMBODU
YvOVhZQ46Iss9ANc0QZzTGJR2S0IFcNmf8es22WtqzQLiNgByiq4C3Ee3GfS
VRQinOQFCAumzhtke1QSIPaVpYG7FGaXHBNHvo+h9BGRnIQXQdgI9DNFcyyw
JEpetffugI+pMd2l5dIeaAAyq35LCcAJ0QAIj/A8Ld4PKvT8tGm4DkhWhcKI
k133gRXhmFQa04JYvB3gDVKI1mdLechOTMgINBT2FrOwGFV5qUQiBPMQaAzL
EN4KYE2os4uapckqhIssDLHBKqSKwEGoCDC3BwE6wi5MgxFuVspsoFKgDYKM
IXmSEsxCbwvytHgJAhGJUXz0ZDgI9qMvFkjd7fQC4wQjacWUOcGgidAYCeFn
XOQMj0e9jbaaAEQNPLNTe9ByOuEmMfudR/ggVT7CWgdTNQNarIK2NWCuCZif
wmrMGORAV8AdVaSMCXkaCBmnv8gxIYfoMTKy4UVtqpBsv8EYC4vLEtYtlxGf
Ray1i/3aAtbMV0/RIiDAkIhFfh6CiTaRonRgXIpLg0FbuqQIgcuGRBoE8B80
43xQhariSjiGufRAQC8cXAnBf2jKYsttB/wv0CIgXbzgpd+cwl5RhXzYViB8
aV4/y/iFSyP/AHwVyViuaAEA

-->

</rfc>
